AnyConnect VPN full tunnel could not access the site to site VPN

I have a set of AnyConnect VPN upward with no split tunneling (U-turning/crossed traffic), running 8.2.5 code.

It works fine, but I want to allow customers to AnyConnect VPN site to site, which I was unable to access.

I checked the IP addresses of network anyconnect are part of the tunnel on both sides.

My logic tells me that I must not turn back traffic from the network anyconnect for the site to site VPN, but I don't know how to do this.

Any help would be appreciated.

Here are the relevant parts of my config:

(Domestic network is 192.168.0.0/24,

the AnyConnect network is 192.168.10.0/24,

site to site VPN network is 192.168.2.0/24)

--------------------------------------------------------------------------------------

permit same-security-traffic inter-interface
permit same-security-traffic intra-interface

the DM_INLINE_NETWORK_1 object-group network
object-network 192.168.0.0 255.255.255.0
object-network 192.168.10.0 255.255.255.0
inside_nat0_outbound list extended access allowed object-group ip DM_INLINE_NETWORK_1 192.168.2.0 255.255.255.0
permit access ip 192.168.0.0 scope list inside_nat0_outbound 255.255.255.0 192.168.10.0 255.255.255.0

outside_1_cryptomap list extended access allowed object-group ip DM_INLINE_NETWORK_1 192.168.2.0 255.255.255.0

mask 192.168.10.2 - 192.168.10.254 255.255.255.0 IP local pool AnyConnectPool
Global 1 interface (outside)
NAT (inside) 0-list of access inside_nat0_outbound
NAT (inside) 1 0.0.0.0 0.0.0.0
NAT (outside) 1 192.168.10.0 255.255.255.0
access-outside group access component software snap-in interface outside
Route outside 0.0.0.0 0.0.0.0 (the gateway IP) 1
WebVPN
allow outside
AnyConnect essentials
SVC disk0:/anyconnect-win-3.1.05152-k9.pkg 1 image
SVC profiles AnyConnectProfile disk0: / anyconnect_client.xml
enable SVC
tunnel-group-list activate
internal AnyConnectGrpPolicy group strategy
attributes of Group Policy AnyConnectGrpPolicy
WINS server no
value of 192.168.0.33 DNS server 192.168.2.33
VPN-session-timeout no
Protocol-tunnel-VPN l2tp ipsec svc
Split-tunnel-policy tunnelall
the address value AnyConnectPool pools
type tunnel-group AnyConnectGroup remote access
attributes global-tunnel-group AnyConnectGroup
address pool AnyConnectPool
authentication-server-group SERVER1_AD
Group Policy - by default-AnyConnectGrpPolicy
tunnel-group AnyConnectGroup webvpn-attributes
the aaa authentication certificate
activation of the Group _AnyConnect alias

Your dial-up VPN traffic as originating apears on the external interface, so I think you need to exonerate NAT pool PN traffic directed to the site to site VPN. Something like this:

 global (outside) 1 interface nat (inside) 0 access-list inside_nat0_outbound nat (inside) 1 0.0.0.0 0.0.0.0 nat (outside) 0 access-list outside_nat0 nat (outside) 1 192.168.10.0 255.255.255.0 access-list outside_nat0 extended permit ip any 192.168.10.0 255.255.255.0 access-list inside_nat0_outbound extended permit ip 192.168.0.0 255.255.255.0 192.168.10.0 255.255.255.0

Tags: Cisco Security

Similar Questions

  • The user * address email is removed from the privacy * could not connect, could not access the directory.

    For the second time in the last two weeks going through my event logs, I noticed several hundred newspaper failed attempts at the course over a period of twenty minutes.  they are random user accounts that don't exist not user 1, user 2, www., or just names at random, the papers say newspaper caused by a wrong password or account.  "the first of these events several connected has this message:" user * address email is removed from the privacy * could not connect, could not access the directory. ».  What does that mean?  Do you need access and control my computer?  Any info would be a great help.

    Looks like someone trying to log on your computer.  Check your firewall settings to make sure that they can't.

    Visit https://www.grc.com/x/ne.dll?bh0bkyd2 the site "shields up" to perform a check.  Some people to dismiss the guy who runs it, but the test doesn't show you which allows your computer to the world to see.
  • Could not access the value of the component off ValueChangeListener

    In many cases, I need to use the value of some UIComponent during execution in many places in the application. But the problem is that I could not access the value of the component outside the ValueChangeListener of this component. I tried to store this value in a temporary local variable, I also tried to use the opportunity to link , but it did not work.

    This thread changes made on the ValueChangeListener can't think where else

    said I should go ahead everything in the ValueChangeListener but is not useful in my case and it's really limit my choice later.

    So question is: How to access the value of the element external ValueChangeListener?

    I use Jdeveloper with ADF 11.1.2.3 technology

    Hello

    You can create a bean (depending on the application, choose the scope), add a variable with accessors and then use it in the 'value' property of the component.

    Arun-

  • Whenever I try to install and update creative cloud, he's going to halfway and stop the download says "Setup could not access the critical file (error code46).

    Whenever I try to install and update creative cloud, he's going to halfway and stop the download says "Setup could not access the critical file (error code46).

    Hello

    Please refer to the instructions mentioned in the link below, it should help:

    Cannot install Creative cloud installation - error code 46

    "Setup could not access a critical file. Please try to reinstall. (error code: 46) »

    Stop creating cloud download

    Let us know if this was helpful.

    Kind regards

    Bani

  • I'm trying to upgrade a site from Muse and it keeps telling me that the site has been created with a different version of Muse. I have updated Muse and still can not access the site to make changes.

    I'm trying to upgrade a site from Muse and it keeps telling me that the site has been created with a different version of Muse. I have updated Muse and still can not access the site to make changes.

    Hi rgarden95,

    Can you please confirm the exact version of Muse, you open the file with?

    To check the version of Muse, please click Help-> on Adobe Muse CC.

    Kind regards

    Akshay

  • RH10: Test connection displays error: could not contact the site at the specified url.

    Hello

    I am using sharepoint as a control source code for my project. Here are the steps mentioned in the link of reference robohelp 10.

    Step 1 & 2 are completed successfully. But in step 3, when I add version control, an error message appears.

    File-> Version Control-> add to version control-> connector Sharepoint RoboHelp-> Ok-> enter Sharepoint site-> test the connection

    Error message: "test connection displays error: could not contact the site at the specified url.» There is no web named *. "/ _vti_bin/sites.asmx.

    Help, please.

    Hello

    Using SharePoint 2010? Earlier versions are not supported for version control.

    What is the URL that you use? You must point RH on the site or subsite holding library. Not the library itself.

    Take a bow

    Willam

  • Internet security problem - I got a security alert was attacking my computer or filtered in and I could not access the internet

    Yes, all of a sudden, I got a security alert was attacking my computer or filtered in and I could not access Internet, I advocate for window / malware scanning and also, mcafee for extra security, but it happens still., why? Then a few days later, I was able to get on the internet again, only about 2 days, now I can no longer access the internet, Iget, open with file, message, so I guess I have to reinstall internet explore, some of my applications are not running, but I think that their always there.  I have scan Windows / Defender and mcafee installed and running on my computer, so what's the problem here?

    Hello

    Download update and scan with the free version of malwarebytes anti-malware

    http://www.Malwarebytes.org/MBAM.php

    You can also download and run rkill to stop the process of problem before you download and scan with malwarebytes

    http://www.bleepingcomputer.com/download/anti-virus/rkill

    If it does not remove the problem and or work correctly in normal mode do work above in safe mode with networking

    Windows Vista

    Using the F8 method:

    1. Restart your computer.
    2. When the computer starts, you will see your computer hardware are listed. When you see this information begins to tap theF8 key repeatedly until you are presented with theBoot Options Advanced Windows Vista.
    3. Select the Safe Mode with networking with the arrow keys.
    4. Then press enter on your keyboard to start mode without failure of Vista.
    5. To start Windows, you'll be a typical logon screen. Connect to your computer and Vista goes into safe mode.
    6. Do whatever tasks you need and when you are done, reboot to return to normal mode.
  • Could not access the Windows Installer service

    I am tring to install .NET Framework 2.0 and windows gives me an error saying that my Windows service install could not be accessed

    I'm tring to appear on an error message received when I tried to download .NET Framework 2.0 it says could not access windows service install and I need this program to the someone can help?

    Hello
    1. are you able to install other programs?

    This problem may occur if one of the following conditions is true:
    1. the Windows Installer files that are on your drive hard are missing or are damaged.
    2. you install or remove a program that uses the package file to install software for the Microsoft install (MSI) Windows (.msi).
     
    To resolve this problem, use the following methods.
    Method 1: Reregister Windows install.
    1. Click Start, type cmd, right-click on cmd, and then click Run as administrator.
    2. at the command prompt type msiexec /unreg and then press ENTER.
    3. at the prompt, type msiexec/regserver, and then press ENTER.
     
    Method 2: Disable the .NET Framework 3.0 before installing .NET Framework 2.0
    Microsoft .NET Framework 3.0 is the default version built into Windows Vista. We recommend that you first cross check if it is enabled in the Windows features turn on or off. To do this, try the following steps.
    1. click on start, type optionalfeatures and press to enter.
    2. in the verification of the list if .NET Framework 3.0 is enabled or disabled. If it is enabled, disable it and restart the computer.
    3. install .NET Framework 2.0 and check the result.
     
    Method 3: Install the latest .NET Framework.
    1. visit the following Web site and download the latest version and install it.
    http://go.Microsoft.com/fwlink/?LinkId=120486
     
    For more information, see this link: http://support.microsoft.com/kb/942288
     
    NOTE: Don't forget to follow method 2 to activate the .NET Framework.
     
    I hope this helps.
     
    Kind regards
    Syed
    Answers from Microsoft supports the engineer.
  • Can not access the site Web of John Lewis, get message server unexpectedly dropped the connection all the time

    Use the iMac with El Capitan 10.11.1 & Safari 9.0.1

    During the last week, I was unable to access the site Web of John Lewis and the message "Safari cannot open page www.johnlewis.com because the server dropped the connection unexpectedly. Sometimes this happens when the server is busy. Wait a few minutes and then try again"I retry but get the same message all the time. Can access all other sites ok.

    I emptied the cache, deleted the cookies and history. Enter the name of the site in its entirety is not helped either.

    Unable to access the Web by John Lewis site with my iPad either.

    Help!

    Try restarting/resetting the router.

    Try a reboot.

    Make a backup using Time Machine or a cloning program, to ensure that data files can be recovered. Two backups are better than one.

    Try to set up another admin user account to see if the same problem persists. If back to my Mac is enabled in system preferences, the guest account will not work. The intention is to see if it is specific to an account or a system wide problem. This account can be deleted later.

    Isolate a problem by using a different user account

    If the problem is still there, try to start safe mode using your usual account.  Disconnect all devices except those necessary for the test. Shut down the computer and then put it up after a 10 second wait. Immediately after hearing the startup chime, hold down the SHIFT key and continue to hold it until the gray Apple icon and a progress bar appear. Startup is considerably slower than normal. This will reset some caches, forces a check for directory and disables all start-up and connection, among other things. When you restart normally, the initial restart may be slower than normal. If the system is operating normally, there may be 3rd party applications that pose a problem. Try to delete/disable the third-party applications after a reboot using the UN-Installer. For each disable/remove, you need to restart if you do them all at once.

    Safe mode - on El Capitan

    Start Mode without failure-El Capitan.

  • Could not access the external hard drive on the WRT610N

    I recently bought the WRT610N router and updated the firmware version 1.00.02 B10 on it. I also have a 500 GB WD Caviar Green hard drive in an external enclosure to Koutech EEC320. I wanted to connect my HD in a configuration server network via the USB port on the router.

    The first time I hooked it up, everything worked for the most part very well: I could go to the tab of storage on the utility line of router, put in place actions and other things. The problem was that I could not really give administrator rights to access the actions I put in place on the hard drive, so I couldn't change the files or anything like that. I would try to put in place the administrative privileges in the sharing settings, but they would never appear in the summaries of the part. I even tried to change the share name of the 'Default' which appears at random at one time, but this caused the group to disappear her privileges, and the 'failure' share to disappear (although the usefulness of reserves still the name for him) which means I can't do another flaw).

    I have reset the router to try to get the sharing by default return, but now whenever I try to access the storage in the router utility tab, I get a blank screen, so I can't recreate all the actions on my HD Plus, every tab I try to access after the who end up in a screen blank until I restart my browser where all is well until I try to access the store again. This happens even after resetting the router several times and even reinstall the firmware once.

    Any ideas on how to solve this problem in order to access and edit files on my hard drive through my network?

    Yay! I got 'Default' on my HD! Now, it would be great if I could add permissions to actions so I can add more readers...

  • Error 1606: Could not access the location network 0

    Every time I download any software with msi.exe, the software interface says first "Computing space required" and follows this error message "Error 1606 could access the network 0 location . "

    I've used windows install Cleanup utility software and also used the link "start > run > Regedit >... > recent removal."  Yet the problem persists

    Sincerely, Kelly Kelly

    This problem occurs because there is incorrect entries in the Shell folder of the user who is logged on to Microsoft Windows. When Windows Installer goes to the sale of Shell folder of the user who is logged on to the computer, Windows Installer cannot locate the correct entry. The solution is in http://support.microsoft.com/default.aspx/kb/886549.

    The steps to correct this problem involve editing the Windows registry.  Change the settings of the REGISTRY can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the REGISTRY settings configuration can be solved. Changes to these settings are at your own risk.  I suggest that you first back up your registry as follows: http://windows.microsoft.com/en-US/windows-vista/Back-up-the-registry.

    Here are the steps to fix it.

    1. click on start, run, type regedit in the Open box, and then click OK.

    2. look for the following registry key:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell dossiers\

    3 remove the entries that show the path that is listed in the error message.

    886549 KB http://support.microsoft.com/default.aspx/kb/886549: Regedit open again. In the left pane, click User Shell Folders, point to new, click expandable string value, type the value name that you want to restore (AppData) and then press ENTER. Right click on this value, click change, type the value in the value data for the value name box, and then click OK. The value data must be: % USERPROFILE%\AppData\Roaming.

    Step 8 KB 886549 suggests that you also check the values in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders. However, by fixing my problem, I had not to change values in the registry key.  If this does not work, follow ALL the steps in the referenced article.

    Good luck.

    Lorien - MCSA/MCSE/network + / has + - if this post solves your problem, please click the 'Mark as answer' or 'Useful' button at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • Could not access the internet via third party application

    Hi Forum members,

    I develop a thrid party application, which makes http calls to retrieve the data.

    Perfectly on Simulator to work.

    I'm testing this app on BB 9000 "BOLD", he is not able to do an HTTP call.

    Code:

    http = (HttpConnection) Connector.open (URL);

    invalid url parameter of returns.

    Kindly let me know what changes I need to do on my "BOLD", I am a newbie and don't know much about it.

    I'm not able to go forward because of this error.

    Thank you and best regards.

    (1) "I had a Word with vodafone CC, they told me that we must have the BES server in our company, only then my device can become."

    a BES device, so I guess I won't be able to test MDS in the Network Diagnostics tool, am I rite? »

    You are right.

    (2) "even if we need to test the WAP option in the same tool, we need to provide information such as:

    Gateway APN, gateway ip, gatewa userame, pass, source ip and source port. »

    There are (at least) two versions of WAP.  your comments are correct for the WAP 1.  For WAP 2, if you have directories of Service on the phone, it will automatically connect.  It wouldn't surprise me if you do not have WAP 2.  However, you can read the requirements for WAP 1 and WAP 2 here:

    What - in different ways to establish an HTTP connection or socket
    Article number: DB-00396
    http://www.BlackBerry.com/knowledgecenterpublic/livelink.exe/fetch/2000/348583/800451/800563/What_Is...

    (3) "contains the information required to connect to a provider wireless WAP 1.x gateway.

    Legacy AT & T wireless only subscribers: Contains the information required to connect to the carrier's WAP gateway.

    does that mean vodafone will not support the WAP1.x and any third-party application cannot test this option as well. »

    No - it means settings that you find on this site are specific for att devices.  You will have to find the equivalent information for the Vodafone India.

  • Error 1606. Could not access the location network 0. during the installation of 2013 Wisconsin State tax return.

    Windows 8 - PC

    HP Envy m6

    This error occurs when I try to install (restore) my Wisconsin State 2013 by HR Blocktax return.

    • Clean the registry.
    • Disabled Windows Defender briefly.
    • Clean boot today.
    • Approximately 45 minute online chat with block of HR who instructed me to clean the boot.

    This error message occurs every time I have something new to try to help the problem. Oh, ended up buying PC Cleaner Pro to clean the registry and not only did - she did not help, they don't respond to emails through their contact page.

    Help, please!

    Hi Kathleen,.

    To better understand the issue, let me know if you face any problem during the installation of other programs?

    I appreciate your efforts to solve this problem. This problem could occur due to damaged user account or damaged registry keys.

    Try the steps listed here and see if it helps.

    Method 1:
    I suggest you run the fixit who will repair the issues that block program installation or removal because of corrupted registry keys.

    The problems that the programs cannot be installed or uninstalled
    http://support.Microsoft.com/mats/Program_Install_and_Uninstall

    Method 2:
    If the problem persists, we will check whether the product is on a new user account (Administrator).

    Create a user account
    http://Windows.Microsoft.com/en-us/Windows/create-user-account#create-user-account=Windows-8

    Hope this information helps. Reply to the post with an up-to-date report of the issue so that we can help you further.

  • While the research on how to correct an error in the observer of events, W32 tried merging a .reg file and got an error message saying could not access the registry, why?

    http://www.techexams.NET/blogs/jdmurray/synchronizing-the-time-on-Windows-XP-and-Vista-with-the-Internet/

    Hello, I'm under win xp pro svc pk 3, ie 8, x32bit.

    I received an error in the Event Viewer system for time synchronization W32. Help box said not to worry if it's a computer for the home user, but I'm tired of doing all the time, every day, so I tried to find a way to get rid of it. On bing, I found the above Web site and tried to merge the nist servers in my registry but I kept getting msg. :

    Impossible to import c:\doc and set\adm\dsktop\timeservers.reg: the specified file is not a registry script. You can only import binary registry files in the registry editor.

    the first msg not acceding, and I guess it was because I had the registry open at the same time. Anyway after that I couldn't import, just add the items in the registry manually.

    My question is, really, was performed correctly by the copy of the list of servers of time in the text, paste it into a file and you try to merge?

    Appreciate any assistance with this issue.

    Just for info:

    If you see a message similar to the following:

    Impossible to import c:\Documents and Settings\Jose\Desktop\enableit.reg: the specified file is not a registry script.
    You can only import binary registry files in the registry editor.

    That means either that your registry import file is missing the top line (or it's the wrong syntax):

    Windows Registry Editor Version 5.00

    or the file you are trying to import is not a valid registry import file.

  • "Error 1606. Could not access the location network O."

    Microsoft KB 886549 does not resolve this issue.

    Problem solved.  Windows Installer Clean Up correctly deleted the H & R Block - entry KS State.

Maybe you are looking for