Question
July 28, 2008 at 02:30 PM
paul

ASA 5505 VPN cannot connect to Static NAT

by paul . Updated 18 years ago

Hello,

I have setup a VPN on a ASA 5505. I can connect fine and Ping any internal address except for the ones I have Static NATs setup for to point to external IPs.

Can anyone help me work past this? I am enclosing my current config:

: Saved
:
ASA Version 7.2(2)
!
hostname psllc-pix
domain-name ps-cpa.com
enable password 6R.OGtQE9saHiedH encrypted
names
name 192.168.254.250 mainsrv-in
name 10.10.0.251 citrix-out
name 192.168.254.251 citrix-in
name 10.10.0.251 mainsrv-out
!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.254.254 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address 10.10.0.217 255.255.255.248
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
clock timezone CST -6
clock summer-time CST recurring
dns server-group DefaultDNS
domain-name ps-cpa.com
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
access-list outside_access_in extended permit tcp any eq domain any eq domain
access-list outside_access_in extended permit udp any eq domain any eq domain
access-list outside_access_in extended permit tcp any eq www host mainsrv-out eq www
access-list outside_access_in extended permit tcp any eq smtp host mainsrv-out eq smtp
access-list outside_access_in extended permit tcp any eq https host mainsrv-out eq https
access-list outside_access_in extended permit tcp any eq citrix-ica host citrix-out eq citrix-ica
access-list outside_access_in extended permit tcp any eq www host citrix-out eq www
access-list outside_access_in extended permit tcp any eq https host citrix-out eq https
access-list outside_access_in extended permit tcp any eq 3389 host citrix-out eq 3389
access-list outside_access_in extended permit udp any eq 1604 host citrix-out eq 1604
access-list acl-inbound extended permit icmp any any
access-list acl-inbound extended permit tcp any any eq domain
access-list acl-inbound extended permit udp any any eq domain
access-list acl-inbound extended permit tcp any host mainsrv-out eq smtp
access-list acl-inbound extended permit tcp any host mainsrv-out eq https
access-list acl-inbound extended permit tcp any host citrix-out eq citrix-ica
access-list acl-inbound extended permit udp any host citrix-out eq 1604
access-list acl-inbound extended permit tcp any host citrix-out eq https
access-list acl-inbound extended permit tcp any host mainsrv-out eq www
access-list acl-inbound extended permit tcp any host citrix-out eq 3389
access-list ps-cpa-vpn_splitTunnelAcl standard permit 192.168.254.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip any 192.168.254.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip 192.168.254.0 255.255.255.0 192.168.254.0 255.255.255.0
access-list psvpn_splitTunnelAcl standard permit 192.168.254.0 255.255.255.0
access-list client_vpn extended permit ip any 192.168.254.0 255.255.255.0
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
ip local pool psvpnpool 192.168.254.150-192.168.254.180 mask 255.255.255.0
ip verify reverse-path interface outside
no failover
monitor-interface inside
monitor-interface outside
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-522.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
global (outside) 1 10.10.0.220
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) citrix-in citrix-out netmask 255.255.255.255
static (inside,outside) mainsrv-in mainsrv-out netmask 255.255.255.255
static (inside,outside) mainsrv-out mainsrv-in netmask 255.255.255.255
static (inside,outside) citrix-out citrix-in netmask 255.255.255.255
access-group acl-inbound in interface outside
route outside 0.0.0.0 0.0.0.0 10.10.0.222 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
aaa-server PS-CPA-VPN protocol ldap
aaa-server PS-CPA-VPN host mainsrv-in
ldap-base-dn OU=Users,DC=company,DC=com
ldap-scope onelevel
ldap-login-password *
ldap-login-dn CN=Administrator,OU=Users,DC=company,DC=com
server-type microsoft
group-policy DfltGrpPolicy attributes
banner none
wins-server none
dns-server none
dhcp-network-scope none
vpn-access-hours none
vpn-simultaneous-logins 3
vpn-idle-timeout 30
vpn-session-timeout none
vpn-filter value client_vpn
vpn-tunnel-protocol IPSec l2tp-ipsec webvpn
password-storage disable
ip-comp disable
re-xauth disable
group-lock none
pfs disable
ipsec-udp enable
ipsec-udp-port 10000
split-tunnel-policy tunnelall
split-tunnel-network-list none
default-domain none
split-dns none
intercept-dhcp 255.255.255.255 disable
secure-unit-authentication disable
user-authentication disable
user-authentication-idle-timeout 30
ip-phone-bypass disable
leap-bypass disable
nem disable
backup-servers keep-client-config
msie-proxy server none
msie-proxy method no-modify
msie-proxy except-list none
msie-proxy local-bypass disable
nac disable
nac-sq-period 300
nac-reval-period 36000
nac-default-acl none
address-pools none
client-firewall none
client-access-rule none
webvpn
functions url-entry
html-content-filter none
homepage none
keep-alive-ignore 4
http-comp gzip
filter none
url-list none
customization value DfltCustomization
port-forward none
port-forward-name value Application Access
sso-server none
deny-message value Login was successful, but because certain criteria have not been met or due to some specific group policy, you do not have permission to use any of the VPN features. Contact your IT administrator for more information
svc none
svc keep-installer installed
svc keepalive none
svc rekey time none
svc rekey method none
svc dpd-interval client none
svc dpd-interval gateway none
svc compression deflate
group-policy ps-cpa-vpn internal
group-policy ps-cpa-vpn attributes
banner value These systems are for use by employees of Pasquesi Sheppard.
wins-server value 192.168.254.250
dns-server value 192.168.254.250
vpn-access-hours none
vpn-simultaneous-logins 3
vpn-idle-timeout none
vpn-session-timeout none
vpn-filter value client_vpn
vpn-tunnel-protocol IPSec l2tp-ipsec webvpn
ipsec-udp enable
ipsec-udp-port 10000
split-tunnel-policy tunnelspecified
split-tunnel-network-list value ps-cpa-vpn_splitTunnelAcl
default-domain value ps-cpa.com
address-pools value psvpnpool2
webvpn
customization none
vpn-group-policy ps-cpa-vpn
http server enable
http 192.168.254.0 255.255.255.0 inside
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server community public
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto dynamic-map outside_dyn_map 20 set pfs
crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA
crypto dynamic-map outside_dyn_map 40 set pfs
crypto dynamic-map outside_dyn_map 40 set transform-set ESP-3DES-SHA
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
crypto isakmp nat-traversal 20
crypto isakmp ipsec-over-tcp port 10000
tunnel-group DefaultWEBVPNGroup general-attributes
default-group-policy company-vpn
dhcp-server mainsrv-in
tunnel-group DefaultWEBVPNGroup webvpn-attributes
tunnel-group ps-cpa-vpn type ipsec-ra
tunnel-group ps-cpa-vpn general-attributes
address-pool psvpnpool
authentication-server-group company-VPN
default-group-policy company-vpn
dhcp-server mainsrv-in
tunnel-group company-vpn ipsec-attributes
pre-shared-key *
no vpn-addr-assign aaa
no vpn-addr-assign dhcp
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!

!
!
webvpn
enable outside
prompt hostname context
Cryptochecksum:6f2ac1c58bbec61ec7ca943584f24f81
: end
asdm image disk0:/asdm-522.bin
no asdm history enable

This discussion is locked

All Comments