Impossible to access all subnets when connected by VPN

I'm a total newbie when it comes to cisco and routing, so forgive me if this has been answered before.

We have a cisco 2821 router which supports VPN connections. Our local network is a 22 (255.255.252.0) xxx.xxx.0.0 xxx.xxx.1.0 xxx.xxx.2.0 xxx.xxx.3.0 subnets. I can connect by VPN, and I can access my xxx.xxx.1.0 subnet with no problems. However, I can't access the subnets xxx.xxx.2.0 and xxx.xxx.3.0.

I don't know even where to start. I have seen similar topics but I need "dumbed down" for me. Preference of the solutions that I can apply through the SDM. I'm terrible with the CLS.

Thanks for any help provided! :-)

It's here

access-list 199 permit ip 10.1.0.0 0.0.1.255 10.1.255.0 0.0.0.255

your customers receive the address pool of 10.1.255.0 0.0.0.255

to allow access to any other network in your local network from the vpn client

access-list 199 permit ip 10.1.255.0 0.0.0.255

You must add the same lines that you add in the 199 ACL ACL 104 but with the action to refuse since you are using nat

104 refuse 10.1.0.0 ip access-list 0.0.1.255 10.1.255.0 0.0.0.255

Notice that you use a deny and that is to tell the router to do no. NAT traffic.

I hope that helps... Let me know

Tags: Cisco Security

Similar Questions

  • My computer can not VAT registration and access the internet when connected to the network [secure] through wireless.

    Original title: fix problem 'local only' what is wireless.
     
    -My computer is a HP Pavilion dv5, running windows vista edition Home premium

    -My computer can identify and access the internet when connected to the network through a cable.

    -My computer can identify and access the internet when it is connected to the grace wireless network [without warranty].
    -My computer can't identify [unidentified network] and [room only] internet access when it is connected to the [secure] grace wireless network?
    -Other information systems, identify and access the internet when it is connected to the [secure] grace wireless network.
    -J' confirmed the network, try password works in "safe mode with network", manually configured (TCP/IPv4) using a connected computer.
    S ' Please, I'm desperate and in urgent need of help.

    Hello

    1. If it works well before?

    2 have you made any changes to the computer before the show?

    Method 1:

    You may experience connectivity problems or performance issues when you connect a portable computer that is running Windows Vista or Windows 7 to a wireless access point:
    http://support.Microsoft.com/kb/928152

    Method 2: Uninstall and reinstall the network adapter drivers.

    Follow the steps mentioned.

    (a) click Start, right click on computer.
    (b) click on properties, click on Device Manager
    (c) expand the network card, right-click the wireless adapter option
    (d) click on uninstall
    (e) now go to your computer/wireless device manufacturer's website, download the updated drivers and install them.

    Follow the below mentioned article:
    Updated a hardware driver that is not working properly
    http://Windows.Microsoft.com/en-us/Windows-Vista/update-a-driver-for-hardware-that-isn ' t-work correctly

  • Difficulty accessing 1 remote desktop when connected with VPN

    Hello world

    I have an ASA 5505 and have a problem where when I connect via VPN, I can RDP into a server using its internal address but I can't RDP to another server using its internal address.

    One that I can connect to a an IP of 192.168.2.10 and I can't connect to a a 192.168.2.11 on 3390 port IP address.

    The two rules are configured exactly the same except for the IP addresses and I can't see why I can't connect to this server.

    I am also able to connect to my camera system with an IP on port 37777 192.168.2.25 and able to ping any other device on the network internal.

    I also tried ping he and Telnet to port 3390 without success.

    Here is the config.

    ASA 4,0000 Version 1

    !

    !

    interface Ethernet0/0

    switchport access vlan 3

    !

    interface Ethernet0/1

    !

    interface Ethernet0/2

    switchport access vlan 2

    !

    interface Ethernet0/3

    !

    interface Ethernet0/4

    !

    interface Ethernet0/5

    !

    interface Ethernet0/6

    !

    interface Ethernet0/7

    !

    interface Vlan2

    nameif inside

    security-level 100

    IP 192.168.2.2 255.255.255.0

    !

    interface Vlan3

    nameif outside

    security-level 0

    10.1.1.1 IP address 255.255.255.0

    !

    passive FTP mode

    clock timezone IS - 5

    clock to summer time EDT recurring

    network obj_any object

    subnet 0.0.0.0 0.0.0.0

    network of the OWTS-LAN-OUT object

    10.1.1.10 range 10.1.1.49

    network of the OWTS-LAN-IN object

    Subnet 192.168.2.0 255.255.255.0

    service of the RDP3389 object

    service destination tcp 3389 eq

    Description of DC

    the object SERVER-IN network

    host 192.168.2.10

    network of the SERVER-OUT object

    Home 10.1.1.50

    network of the CAMERA-IN-TCP object

    Home 192.168.2.25

    network of the CAMERA-OUT object

    Home 10.1.1.51

    service object CAMERA-TCP

    Service tcp destination eq 37777

    the object SERVER-Virt-IN network

    Home 192.168.2.11

    network of the SERVER-Virt-OUT object

    Home 10.1.1.52

    service of the RDP3390 object

    Service tcp destination eq 3390

    Description of VS for Master

    network of the CAMERA-IN-UDP object

    Home 192.168.2.25

    service object CAMERA-UDP

    Service udp destination eq 37778

    the object OWTS LAN OUT VPN network

    subnet 10.1.1.128 255.255.255.128

    the object SERVER-Virt-IN-VPN network

    Home 192.168.2.11

    the object SERVER-IN-VPN network

    host 192.168.2.10

    the object CAMERA-IN-VPN network

    Home 192.168.2.25

    object-group Protocol TCPUDP

    object-protocol udp

    object-tcp protocol

    AnyConnect_Client_Local_Print deny ip extended access list a whole

    AnyConnect_Client_Local_Print list extended access permit tcp any any eq lpd

    Note AnyConnect_Client_Local_Print of access list IPP: Internet Printing Protocol

    AnyConnect_Client_Local_Print list extended access permit tcp any any eq 631

    print the access-list AnyConnect_Client_Local_Print Note Windows port

    AnyConnect_Client_Local_Print list extended access permit tcp any any eq 9100

    access-list AnyConnect_Client_Local_Print mDNS Note: multicast DNS protocol

    AnyConnect_Client_Local_Print list extended access permit udp any host 224.0.0.251 eq 5353

    AnyConnect_Client_Local_Print of access list LLMNR Note: link Local Multicast Name Resolution protocol

    AnyConnect_Client_Local_Print list extended access permit udp any host 224.0.0.252 eq 5355

    Note access list TCP/NetBIOS protocol AnyConnect_Client_Local_Print

    AnyConnect_Client_Local_Print list extended access permit tcp any any eq 137

    AnyConnect_Client_Local_Print list extended access udp allowed any any eq netbios-ns

    implicit rule of access-list inside1_access_in Note: allow all traffic to less secure networks

    inside1_access_in of access allowed any ip an extended list

    outside_access_in list extended access allowed object RDP3389 any host 192.168.2.10

    outside_access_in list extended access allowed object RDP3390 any host 192.168.2.11

    outside_access_in list extended access allowed object CAMERA TCP any host 192.168.2.25

    outside_access_in list extended access allowed object CAMERA UDP any host 192.168.2.25

    pager lines 24

    Enable logging

    exploitation forest-size of the buffer 10240

    asdm of logging of information

    Within 1500 MTU

    Outside 1500 MTU

    local pool RAVPN 10.1.1.129 - 10.1.1.254 255.255.255.128 IP mask

    no failover

    ICMP unreachable rate-limit 1 burst-size 1

    don't allow no asdm history

    ARP timeout 14400

    NAT static destination SERVER-IN-VPN SERVER-IN-VPN (indoor, outdoor) static source OWTS LAN OUT VPN OWTS-LAN-OUT-VPN

    NAT static destination of CAMERA-IN-VPN VPN-IN-CAMERA (indoor, outdoor) static source OWTS LAN OUT VPN OWTS-LAN-OUT-VPN

    NAT static destination of SERVER Virt-IN-VPN-SERVER-Virt-IN-VPN (indoor, outdoor) static source OWTS LAN OUT VPN OWTS-LAN-OUT-VPN

    !

    network of the OWTS-LAN-IN object

    NAT dynamic interface (indoor, outdoor)

    the object SERVER-IN network

    NAT (inside, outside) Shared SERVER-OUT service tcp 3389 3389

    network of the CAMERA-IN-TCP object

    NAT (inside, outside) static CAMERA-OFF 37777 37777 tcp service

    the object SERVER-Virt-IN network

    NAT (inside, outside) Shared SERVER-Virt-OUT 3390 3390 tcp service

    inside1_access_in access to the interface inside group

    Access-group outside_access_in in interface outside

    Route outside 0.0.0.0 0.0.0.0 10.1.1.2 1

    Timeout xlate 03:00

    Pat-xlate timeout 0:00:30

    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00

    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00

    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute

    timeout tcp-proxy-reassembly 0:01:00

    Floating conn timeout 0:00:00

    dynamic-access-policy-registration DfltAccessPolicy

    identity of the user by default-domain LOCAL

    Enable http server

    http 192.168.2.0 255.255.255.0 inside

    No snmp server location

    No snmp Server contact

    Server enable SNMP traps snmp authentication linkup, linkdown warmstart of cold start

    Crypto ipsec transform-set ikev1 ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-DES-SHA esp - esp-sha-hmac

    Crypto ipsec transform-set ikev1 SHA-ESP-3DES esp-3des esp-sha-hmac

    Crypto ipsec transform-set ikev1 esp ESP-DES-MD5-esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-3DES-MD5-esp-3des esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-256-SHA esp-aes-256 esp-sha-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-128-SHA aes - esp esp-sha-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-192-SHA esp-aes-192 esp-sha-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-128-MD5-esp - aes esp-md5-hmac

    crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 pfs Group1 set

    crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 define ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA MD5-ESP-3DES ESP

    DES-SHA ESP-DES-MD5

    outside_map card crypto 65535-isakmp dynamic ipsec SYSTEM_DEFAULT_CRYPTO_MAP

    outside_map interface card crypto outside

    Crypto ca trustpoint ASDM_TrustPoint0

    Terminal registration

    name of the object CN = SACTSGRO

    Configure CRL

    Crypto ikev1 allow outside

    IKEv1 crypto policy 10

    authentication crack

    aes-256 encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 20

    authentication rsa - sig

    aes-256 encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 30

    preshared authentication

    aes-256 encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 40

    authentication crack

    aes-192 encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 50

    authentication rsa - sig

    aes-192 encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 60

    preshared authentication

    aes-192 encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 70

    authentication crack

    aes encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 80

    authentication rsa - sig

    aes encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 90

    preshared authentication

    aes encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 100

    authentication crack

    3des encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 110

    authentication rsa - sig

    3des encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 120

    preshared authentication

    3des encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 130

    authentication crack

    the Encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 140

    authentication rsa - sig

    the Encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 150

    preshared authentication

    the Encryption

    sha hash

    Group 2

    life 86400

    Telnet 192.168.2.0 255.255.255.0 inside

    Telnet timeout 15

    SSH 192.168.2.0 255.255.255.0 inside

    SSH timeout 5

    SSH version 2

    SSH group dh-Group1-sha1 key exchange

    Console timeout 15

    dhcpd auto_config inside

    !

    a basic threat threat detection

    statistical threat detection port

    Statistical threat detection Protocol

    Statistics-list of access threat detection

    no statistical threat detection tcp-interception

    WebVPN

    username admin privilege 15 xxxxx encrypted password

    attributes of user admin name

    VPN-group-policy DfltGrpPolicy

    type tunnel-group CTSGRA remote access

    attributes global-tunnel-group CTSGRA

    address RAVPN pool

    IPSec-attributes tunnel-group CTSGRA

    IKEv1 pre-shared-key *.

    !

    class-map inspection_default

    match default-inspection-traffic

    !

    !

    Policy-map global_policy

    class inspection_default

    inspect the icmp

    !

    global service-policy global_policy

    context of prompt hostname

    no remote anonymous reporting call

    Cryptochecksum:0140431e7642742a856e91246356e6a2

    : end

    Thanks for your help

    Ok

    So, basically, you set up the router so that you can directly connect to the ASA using the Cisco VPN Client. And also, the goal was ultimately only allow traffic to the LAN through the VPN Client ONLY connection.

    It seems to me to realize that you have only the following configurations of NAT

    VPN Client NAT0 / free of NAT / identity NAT

    the object of the LAN network

    Subnet 192.168.2.0 255.255.255.0

    network of the VPN-POOL object

    subnet 10.1.1.128 255.255.255.128

    NAT static destination LAN LAN (indoor, outdoor) static source VPN-VPN-POOL

    The NAT configuration above is simply to tell the ASA who don't do any type of NAT when there is traffic between the network 192.168.2.0/24 LAN and VPN 10.1.1.128/25 pool. That way if you have additional hosts on the local network that needs to be connected to, you won't have to do any form of changes to the NAT configurations for customer VPN users. You simply to allow connections in the ACL list (explained further below)

    Failure to PAT

    object-group network by DEFAULT-PAT-SOURCE

    object-network 192.168.2.0 255.255.255.0

    NAT automatic interface after (indoor, outdoor) dynamic source by DEFAULT-PAT-SOURCE

    This configuration is intended just to replace the previous rule of PAT dynamic on the SAA. I guess that your router will do the translation of the ASA "outside" IP address of the interface to the public IP address of routers and this configuration should allow normal use of the Internet from the local network.

    I suggest you remove all other NAT configurations, before adding these.

    Control of the VPN clients access to internal resources

    Also, I assume that your current VPN client is configured as full Tunnel. In other words, it will tunnel all traffic to the VPN connection, so that its assets?

    To control traffic from the VPN Client users, I would suggest that you do the following

    • Set up "no sysopt permit vpn connection"

      • This will change the ASA operation so that connections through a VPN connection NOT allowed by default in order to bypass the ACL 'outside' interface. So, after this change, you can allow connections you need in the 'outer' interface ACL.
    • Configure rules you need for connections from VPN clients to the "external" ACL interface. Although I guess they already exist as you connect there without the VPN also

    I can't say this with 100% certainty, but it seems to me that the things above, you should get to the point where you can access internal resources ONLY after when you have connected to the ASA via the connection of the VPN client. Naturally take precautions like backups of configuration if you want to major configuration changes. If you manage remotely the ASA then you also also have the ability to configure a timer on the SAA, whereupon it recharges automatically. This could help in situations where a missconfiguration breaks you management connection and you don't have another way to connect remotely. Then the ASA would simply restart after that timer missed and also restart with the original configuration (as long as you did not record anything between the two)

    Why you use a different port for the other devices RDP connection? I can understand it if its use through the Internet, but if the RDP connection would be used by the VPN Client only so I don't think that it is not necessary to manipulate the default port 3389 on the server or on the SAA.

    Also of course if there is something on the side of real server preventing these connections then these configuration changes may not help at all.

    Let me know if I understood something wrong

    -Jouni

  • How can I fix an 'Access denied' error when connecting to mySQL database to a site (I'm sure I can get...)

    Hello

    I had a search on the forums and I don't see anyone with the same problem so I apologize if this has been asked before.

    I need to connect a database to a Web site so that members can register and save it to some pages (not all pages - only a 'members only' section).

    I created the database, tested and it works very well (I used XAMMP/PHPmyAdmin).

    In DreamWeaver CS6, I chose the type of document from the page (PHP) and set up the testing server. If I go to site Configuration > server for the site and click on test, it connects successfully. Note that the test server is hosted at the University, that I work - there is a password required, but I entered it on the test set up server and it seems connects very well, as I get the message successfully at this stage.

    When I go to connect the mySQL connection and select the database I get the error "access is denied. The file exists may not, or there could be a permission problem. Make sure you have permission on the server and the server is properly configured. »

    Any ideas? It's driving me crazy!

    I understand that after several unsuccessful searches on Google, so I post the solution here for someone else with the same question that could end up here.

    If you configure your test server in the inetpub/wwwroot/folder then Dreamweaver cannot make changes (such as adding files) unless you are running as an administrator, so it occurred to me that maybe the database connections are also affected.  Of course, as soon as I leave Dreamweaver and restarted as an administrator, I was able to connect to the MySQL database using the databases Panel.  If you don't know how to run a program as an administrator, it is pretty easy: just right click on Dreamweaver icon and select "Run As Administrator" when you start the program.  There are a lot of tutorials out there that can give you the necessary steps for always loads a program as an administrator if you don't do right click every time.

    Version: Dreamweaver CC 2015.

  • Impossible to reach Vlan system when connecting the Cisco VPN

    Hello

    I has several offices in my position, all my users external are connect to my website using Cisco Client VPN and access my 2 sites, all users are able to access my 2nd Desktop servers that are in the pool of 10.10.0.x, I have a vlan different in the same place with the 10.10.35.x series and users are not able to access this server pool , can someone help me on this I'm not much femilar with routing. I use ASA 5520 firewall.

    Pls help me on this.

    Hari

    I noticed that there is another road on ASA who has 10.10.1.199 nexthop. I did not notice this IP in the list of the interface on the switch. Therefore, another device between ASA and switch?

    All others inside the roads are routed through 10.10.10.36 which is the IP address of the switch, and this swit routes to correct the VLAN. But network 10.10.0.x and now 10.10.35.x are routed through 10.10.1.199.

    What is this IP address?

    Kind regards

    Jan

  • BlackBerry Smartphones Can I created my "BOLD" so that I can access emails only when connected to Wi - Fi?

    I'm not a map of Blackberry, I use the phone via a prepaid sim (it's by Optus in Australia).

    I have correctly set up Wi - Fi and it accessible from several different places (work at home, etc.). I would like to configure e-mail so that it is only through when I'm connected to Wi - Fi. I do know that if I have access to the services of data usually through my prepaid sim card, so I want to make sure that I do not my prepaid if credit I have set up the e-mail function and be able to turn the e-mail function on and off when I like (if you do).

    Can it be done? If so, could you post the instructions. I am a noob to BB and have not used e-mail through BB before.

    Thank you for your help.

    Call your carrier and ask on the price, but with the most basic, you can access e-mail, messenger, etc..

  • IPhone shows not all photos when connected to the computer

    I have an Iphone 5, with more than 800 photos in my camera. When I connect my phone to the computer and open DCIM, happens with 100APPLE, with only 46 photos in the folder, and that's it. I tried to use google reader to get photos from my phone by downloading the app on my phone, but when I tried to add the files it only came with the same 46 photos. I also had a problem where I can't delete photos on my computer when I'm in the Apple folder, and my photos come upwards with one! in a circle in my albums and I'm unable to send them anywhere, and when I click on them, they start to load (as they look blurry when there is the!) but never finished loading. I'm not sure if this is related to the problem, but it could limit. Thank you for your help.

    Here you will find a few troubleshooting steps If you can not import photos from your iPad, iPhone or iPod touch to your computer - Apple Support

  • cannot find the menu view, impossible to access all messages sent. Really STINKS.

    It really stinks can't access my sent messages. Please, put rear view Menu where she was. View menu made it easy for the user like me who have little computer knowledge. What you were doing really sucks bigtime.
    Bryce

    If you try to get toolbars why in the world you unchecked would be those that you had?
    The normal procedure would be to press alt or F10 to display the menu bar, but we've already been there.

  • Why not I access all product when I have a subscription, all exprired after 30 days?

    I have a monthly subscription, but everything I came out it was a trial period of 30 days, I can't use photoshop or lightroom.  What exactly I get my monthly subscription?

    Make sure that you have signed with correct email address

    https://helpx.Adobe.com/creative-cloud/KB/sign-in-out-creative-cloud-desktop-app.html

    If the e-mail address is correct, then check your entries once hosts file

    Log, activation, or connection errors. CS5.5 and later versions

  • When connecting through vpn system get restarted and blue screen in win xp3. How to solve this problem?

    I have everyone!

    I want to connect my people by VPN, once install the vpn and attempt to login system download blue screen and restarted in win xp3. How to solve this problem?

    Hi Satya,

    The question you have posted is related to the VPN connection and would be better suited to the TechNet community.

    Please visit the link below to find a community that will provide the support you want.
    http://social.technet.Microsoft.com/forums/en/itproxpsp/threads
  • Network error mystery - Windows cannot access \\server\users when you use the netbios name, but works fine when you use the full domain name.

    Hi all:

    Mystery - I have a Win 7 work company that cannot access a particular action.  I get the following error-"you are not allowed to access \\server\users.  Contact your network administrator to request access.  However, these users can access these files successfully on other computers, and also if I use the fqdn or the IP instead of the "netbios name server", it connects successfully.

    Environment:

    -Workstation and server at the same time in the same AD Windows 2008 r2 domain.

    -All users, admin and non admin, cannot access this share when connecting to this computer only.

    -ACCESS to the other actions on the same server, as well as actions on other servers.

    -The biggest mystery to me - if I type the FQDN, \\server.domain.local\users, it works!  What the?

    I tried:

    -Deletion of the domain and add it again, no improvement.

    -Check Event Viewer, nothing jumps (not red or yellow).

    -Enabled auditing for access to objects on the server, it does not show a failure in the security event log.

    -Turn off the firewall of my computer.

    -UN-share and re - share the directory.

    -Give everyone full control (the fact that it works well with de facto authorities a little full domain name, a candidate little likely, but I have an open mind).

    For anyone wishing to offer their 'help' by asking me to make some sort of workaround as re - install windows or turn off netbios or use only of the full domain name here on out or whatever, please Don ' t bother.  I appreciate your help, but I am quite able to reinstall and I'm not interested unique hacks that affect this otherwise network well managed, I'm looking for a solution that will allow me to save time and is a long-term solution.

    In my view, that a key point here maybe I can connect successfully using \\server.domain.local\users, but not \\server\users.  Someone at - it some thoughts?

    In DNS server of youe, go to the area in question and in the use of select search before Wins wins tab and enter the address of your wins server if you have one. If not, install one.

  • ASA VPN connection cannot see all subnets

    I'm new to the ASA and I have a problem with our remote users. When people access vpn, they don't see a couple subnets on the network. I looked at the ASA and he can see and communicate with subnets, but when you vpn in them is not reachable. All these connections are connections from admin to admin privlages. Anyone know why the ASA can see subnets, but the admin vpn users cannot?

    You compare your ACL split tunnel and your table routing, but only for networks that are relevant to you and you must have access to and are not outside the old configuration. You should also ensure that these networks can route traffic from the pool of vpn.

  • Allow customers to AnyConnect access to only a few servers when connected

    We have 30 teleworkers that we recently acquired that are put in place with the client AnyConnect to connect to our head of line ASA 5510. For security reasons, we must give them access to only 3 of our servers in-house, all our subnet 10.10.X.X/16. The remotes are published an address via DHCP on the SAA 10.10.50.X/24 when connecting. I thought it would be as simple as creating an access list, but have had no luck in doing so. In addition, we must allow them full access to the servers in a data center connected to our head even ASA via a site to site VPN, while they are connected using AnyConnect. Pointers would be appreciated.

    ASA version 8.3

    Thank you

    -Mike

    You have two choices. You can either apply the ACL as a tunnel of splitting ACL with Group Policy:

    split_tunnel list standard access allowed host 10.10.0.1

    split_tunnel list standard access allowed host 10.10.0.2

    split_tunnel list standard access allowed host 10.10.0.3

    !

    Group Policy GROUP attributes

    Split-tunnel-policy tunnelspecified

    value of Split-tunnel-network-list split_tunnel

    or you can apply ACLs as a vpn-filter o group policy:

    filter_vendor list standard access allowed host 10.10.0.1

    filter_vendor list standard access allowed host 10.10.0.2

    filter_vendor list standard access allowed host 10.10.0.3

    !

    Group Policy GROUP attributes

    VPN-filter value filter_vendor

  • I never use MSN but when I try to uninstall it I get "sorry impossible to uninstall you must be connected to the internet.

    I never use MSN but when I try to uninstall it I get "sorry impossible to uninstall you must be connected to the internet" even though I am connected via DSL how can I overcome this obstacle and uninstall?

    original title: uninstall msn

    Hello

     
    The question you have posted is related to MSN and would be better helped by MSN support. Please visit the link below which offers the best support.
    https://support.MSN.com/default.aspx?mkt=en-us&WA=wsignin1.0&St=1&wfxredirect=1
    For reference:
    How to contact MSN customer service
     
    It will be useful.
  • When I try to connect with my wireless laptop will connect only to Local access. If I connect the laptop to the router with the ethernet cable, it works very well.

    VIsta - Local access only

    HI -.
    I recently moved.   I use the same router from my old apartment and I had no problem connection in the past.   Since I moved I have a new Time Warner modem (Cisco) and the modem works fine.

    The router also works very well I'm able to connect with my iPhone and IPad without any problem.

    But when I try to connect with my wireless laptop, it will only connect to Local access.    If I connect the laptop to the router with the ethernet cable, it works very well.

    It's a Dell Studio 15 with Vista.

    The computer is able to connect to wifi to other places without any problem, but for some reason that I can't connect home.   I tried to reset the modem and the router several times, but that did not help.   I tried the option repair & diagnose several times but it doesn't work.

    I tried to look for other solutions online and tried to disable IPv6, and while it helped some and I was able to connect wireless, the computer ran so slowly that it didn't seem like a good solution.

    This has been very frustrating.   Thanks in advance for any help or suggestion.
    Staci

    Hello Staciusa,

    Have you tried to change the wireless channel that your router is running at? There may be interference that could prevent the internet connection:

    Take a look at step 6 in this article that give more details about it:

    http://www.Microsoft.com/athome/Setup/wirelesstips.aspx

    If you need assistance to change the settings of the specific router, you will need to contact your router manufacturer or your internet service provider.

Maybe you are looking for

  • How can we FF 8 be forced to ignore a site "autocomplete ="off"'?

    AutoComplete for username and password fails in Firefox 8, at least for the sites that have "autocomplete ="off"' in the relevant script." This problem has been solved for FF 3 by editing the fichier...\components\nsLoginManager.js. FF 4 and 8 do not

  • Satellite P100-188 crash nv4.mini.sys

    Hi, new to this forum. Since the P100 188 PSPA3E, new, large laptop for my business including web design/download needs. Only fault in a few months was crack on cover near hinge, which was a common fault at all, that I understand. Never bothered to s

  • Windows on Ideapad Y510P ExpressCache question - gel Constant 8.1

    Hello I recently bought the laptop Y510p and updated to 8.1 windows Since the upgrade, I'm telling gel, which could last 10seconds or 10 minutes. Any time I restart the computer, it crashes, and the only way to kill him is to press the button works /

  • Sound and video malfunction with Windows XP service pack 2

    2 problems: (1) after the update of Windows XP Home Edition (service pack 1) for Windows XP service pack 2 (using update windowns - custom) Media Player often has his crush (not smooth) and there is often no image except the sounds and words on the s

  • 8e5e408 error code

    What does this error code mean?