Solved

ASA AnyConnect tunneling

Posted on 2016-11-18
3
35 Views
Last Modified: 2016-11-18
I have a firewall connected to the internet which doesn't have an inside interface.  The firewall has 2 public IP addresses.  The first public IP address is used for the firewall's outside interface.

I'd like to use the second public IP address to forward traffic to and from a Cisco AnyConnect client.  The client would VPN into the firewall and use the public IP address to communicate with the internet and the internet should be able to initiate connections to the client on port 443.

Right now my VPN works but something's wrong with the NAT rules because I can't access the internet.  After figuring this part out, I'd also like to make sure internet hosts are able to talk to my VPN client on the firewall's public IP address.

ASA.txt
0
Comment
Question by:GuyFaux
  • 3
3 Comments
 

Author Comment

by:GuyFaux
ID: 41893876
Internet access with the secondary public IP has been confirmed.  Now I just need to make sure that requests to the public IP are forwarded to the VPN'ed in client.
0
 

Accepted Solution

by:
GuyFaux earned 0 total points
ID: 41893917
This command makes it work:

object network 192.168.0.1
 nat (outside,outside) static X.X.X.165
0
 

Author Closing Comment

by:GuyFaux
ID: 41893918
Found my own solution.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question