Hot Downloads

Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1
  • 2

TOPIC: VPN Trubbel.Client can connect but not access inside resours

VPN Trubbel.Client can connect but not access inside resours 6 years 7 months ago #34440

  • Marcs
  • Marcs's Avatar
  • Offline
  • New Member
  • Posts: 6
  • Karma: 0
Hello.

I have a problem with my firewall ASA 5505.
Clients can connect through network client and ipsec, but I can not access inside resorces. I can not ping anything inside the firewall.

I have a DC inside but it is not used for DHCP/DNS for the remote clients (instead handled by ASA). Do i have to make any changes to DC or is everything handled by the firewall?

Anyone have time for a quick look plz?
The administrator has disabled public write access.

my running configuration part 1 6 years 7 months ago #34441

  • Marcs
  • Marcs's Avatar
  • Offline
  • New Member
  • Posts: 6
  • Karma: 0
!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address dhcp setroute
!
access-list EGroup_splitTunnelAcl standard permit any
access-list VPN standard permit 192.168.1.0 255.255.255.0
access-list cisco_splitTunnelAcl standard permit any
access-list inside_nat0_outbound extended permit ip any 192.168.120.0 255.255.255.0
ip local pool POOL 192.168.120.1-192.168.120.254 mask 255.255.0.0
The administrator has disabled public write access.

my running configuration part 2 6 years 7 months ago #34442

  • Marcs
  • Marcs's Avatar
  • Offline
  • New Member
  • Posts: 6
  • Karma: 0
service-policy global_policy global
group-policy EGP internal
group-policy EGP attributes
split-tunnel-policy tunnelspecified
split-tunnel-network-list value VPN
username Client password password* encrypted privilege 0
username Client attributes
vpn-group-policy EGP
service-type remote-access
tunnel-group EGP type remote-access
tunnel-group EGP general-attributes
address-pool POOL
default-group-policy EGP
tunnel-group EGP ipsec-attributes
pre-shared-key *
The administrator has disabled public write access.

Re: VPN Trubbel.Client can connect but not access inside resours 6 years 7 months ago #34455

  • Losh
  • Losh's Avatar
  • Offline
  • Distinguished Member
  • Posts: 103
  • Karma: 0
Hi have you tried using Cisco's Security Device Manager (SDM)?

SDM has a check box that allows you to access your LAN while allowing encrypted traffic over the VPN tunnel. Its a really fast way to troubleshoot your VPN without loosing any vital configs. This is under configure/vpn/split tunnel.

Install SDM on your PC/Laptop and access the ASA 5505, it really helps when troubleshooting your config files.

This is risky though! Unless you completely trust your inside network.
~ Networking :- Just when u think its starting to make sense......... ~
____________________________________________
CCNA, CCNP, CCNA Security, JNCIA, APDS, CISA
The administrator has disabled public write access.

Tnks for helping! 6 years 7 months ago #34471

  • Marcs
  • Marcs's Avatar
  • Offline
  • New Member
  • Posts: 6
  • Karma: 0
Unfortionally the SDM is not part of my service agreement :(

And the firewall is part of my home network, so my financial is abit limited...
The administrator has disabled public write access.

Re: VPN Trubbel.Client can connect but not access inside resours 6 years 7 months ago #34493

  • Marcs
  • Marcs's Avatar
  • Offline
  • New Member
  • Posts: 6
  • Karma: 0
:oops:
did you meen ASDM?

Yes I have also been using that tool, (and run the wizard) but the problem still exists. That's why i started this thread.

So nowone can see what's wrong with my config?

BR
Marc
The administrator has disabled public write access.
  • Page:
  • 1
  • 2
Time to create page: 0.081 seconds

CCENT/CCNA

Cisco Routers

  • SSL WebVPN
  • Securing Routers
  • Policy Based Routing
  • Router on-a-Stick

VPN Security

  • Understand DMVPN
  • GRE/IPSec Configuration
  • Site-to-Site IPSec VPN
  • IPSec Modes

Cisco Help

  • VPN Client Windows 8
  • VPN Client Windows 7
  • CCP Display Problem
  • Cisco Support App.

Windows 2012

  • New Features
  • Licensing
  • Hyper-V / VDI
  • Install Hyper-V

Linux

  • File Permissions
  • Webmin
  • Groups - Users
  • Samba Setup