cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
399
Views
3
Helpful
3
Replies

anyconnect VPN anyconnect tunnel all traffic

Hi all,

I have set up the AnyConnect VPN in FMC and allowed all traffic over the tunnel.

I can access any internal network but the VPN client get not connect to Google.com or Cisco.com etc.

When I try to nslookup, the VPN can resolve the IP address 

chocolate2395777_0-1688625115553.png

But can not ping the IP address

chocolate2395777_1-1688625174907.png
chocolate2395777_2-1688625211985.png

I am not sure if is it the NAT issue, but I try the different settings are still the same issues.

chocolate2395777_3-1688625280441.png

Thanks

 

 

 

 

1 Accepted Solution

Accepted Solutions

chocolate2395777_3-1688625280441.png

you need NATing U-turn 
OUTside,OUTside 
check above

View solution in original post

3 Replies 3

@chocolate2395777 you need an Auto NAT rule (in addition to the rule above) to allow the RAVPN traffic to hairpin. With the src and dst interfaces are the "outside" interface, the src network is an object that represents the RAVPN pool and traffic is translated behind the outside interface.

chocolate2395777_3-1688625280441.png

you need NATing U-turn 
OUTside,OUTside 
check above

Thanks so much,

It works, I never thought that need to U-turn.