internal hosts cannot access the internet w / L2L configured tunnel

The internal hosts behind the ASA cannot access the internet with a configured tunnel to L2L. The L2L tunnel is mounted and passing traffic correctly. However, the internal host cannot access the internet through the ASA. I think I have my NAT watered somewhere. I can't even a host statically mapped to the internet. It might be because I'm used to having a WAN IP to the external interface which differs by the CIDR block assigned by the ISP. In this case, it's all together, with the ASA outside interface occupying the first available address.

We have been assigned a CIDR range x.x.x.64/28. x.x.x.65 is my front door and my first usable est.68, by the PSI (I guess what they utilisent.66 et.67 for internal use). External interface of the ASA est.68 and I'm trying to get NAT others. I'm Polo all DHCP clients internal and have some static entries as well. Below is the relevant NAT config. Yet once, all traffic passes above the tunnel properly, but not from inside to outside. If more information is needed, please advise.

interface outside

IP address x.x.x.68 255.255.255.240

NAT-control

Global x.x.x.69 - x.x.x.77 2 (outdoor)

Global 1 x.x.x.78 (outside)

NAT (inside) 0 access-list sheep

NAT (inside) 1 10.10.10.0 255.255.255.0

public static x.x.x.69 (inside, outside) STATIC_NAT_EXAMPLE netmask 255.255.255.255

internal access-group interface inside

Route outside 0.0.0.0 0.0.0.0 x.x.x.65 1

internal to the 10.10.10.0 ip access list allow 255.255.255.0 any

! Remote LAN is 192.168.10.0/24

access-list sheep extended ip 10.10.10.0 allow 255.255.255.0 192.168.10.0 255.255.255.0

Can you post a "show sysopt run?

Try this command to enable proxy arp.

No outside sysopt noproxyarp

Tags: Cisco Security

Similar Questions

Maybe you are looking for

  • SATELLITE P30: the screen is black

    HELLO, RECENTLY I HAVE A STRANGE PROBLEM. ŒUVRES OF PC, BUT THE SCREEN DOES NOT DISPLAY ANYTHING, OR IT ' S BETTER TO SAY THAT HE IS BLACK, BUT IF YOU LOOK CLOSELY, YOU CAN SEE THAT THE IMAGE IS THERE... WHO KNOWS WHAT IS COMING? YOU WANT TO GO TO TH

  • solved: Safari 9.0.3 CMD L

    Greetings, I updated via the AppStore of Mavericks in El Capitan 10.11.3 a few days ago. MacBookPro 4.1 in early 2008. The first was smooth and no problems. Today, Safari started to no longer works with CMD L open location. 1. clear cache 2 deleted h

  • How to make my waveform in the simulation design and control work continuously?

    Hi all, I m a begineer to Labview and have a few question. I use the Labview to design and implement a controller for FOPTD system, but I found that the waveform in the 'loop control and simulation"does not work continuously. I mean keep repeating in

  • error code 0 x 80070643 after installing Windows 7 32 bit on previous Vista

    Tried several browsers; Re-start;  deleted Windows Live one care before installing Windows 7

  • MSG: YOUR SYSTEM IS INFECTED... _

    but when I downloaded and installed the spyware malware removal tool nothing happened... So what I do? Error messages Just rebooted I already tried to solve the problem by installing n downlaoding but the message does not go away