Results 1 to 8 of 8
  1. #1
    Newbie
    Join Date
    Apr 2012
    Posts
    4

    Default VPN Access to Intranet

    I have been trying to get Untangle working for a couple of clients with very similar setups. My issue is getting the laptops to access a private intranet via VPN. The setup works fine without the Untangle server in place. If we put the Untangle server in line the laptops are no longer available to access the intranet. I can access the intranet sites straight from the Untangle box. The laptops VPN to the Cisco ASA and then are able to access server on the LAN and websites on the intranet. From some of the other post I have read it might be the ASA not liking the Untangle there in the middle. Can someone verify this and give me some ideas of things to check on the ASA?

    Thanks,

    Greg
    Attached Images Attached Images

  2. #2
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,893

    Default

    Did you export it? If the IP range of the network isn't exported VPN client's can't touch it.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

  3. #3
    Newbie
    Join Date
    Apr 2012
    Posts
    4

    Default

    Thanks for the reply. I see there are some directions about exporting for the OpenVPN, but I have the clients VPN connection connecting to the ASA. Do I still need to this?

    Thanks,

    Greg

  4. #4
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,893

    Default

    Oh sorry, no that's a different matter.

    I assume you've put a static route into Untangle so it knows where that network is?

    Untangle bridges aren't really bridges, they need a full layer 3 configuration to work properly.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

  5. #5
    Newbie
    Join Date
    Apr 2012
    Posts
    4

    Default

    After doing some reading on here I did add a static route and that did not solve the issue. We have figured out they are not truly a bridge. Even if we stop the IPS data will not flow to that intranet. Luckily at one of my sites they are not using the VPN yet, but they will be very soon. I have to have an IPS/IDS in place for these sites to meet security requirements. I am going to capture some logs off of the ASA and see if I can spot something there. I will post up any finding here.

    Greg

  6. #6
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,893

    Default

    If you create a bypass rule (Config -> Networking -> Advanced -> Bypass) you can make Untangle behave like a normal bridge. Generally speaking Untangle bridges don't like having internal IP ranges coming in from the outside. So I'd try a bypass rule that uses source interface, and the IP range used on the vpn clients and see if that sorts it out.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

  7. #7
    Newbie
    Join Date
    Apr 2012
    Posts
    4

    Default

    I tried creating some bypass rules and it still is not working. I am not sure that I am creating them correct though. Here is what I am getting from the ASA logs.

    %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for udp src outside:192.168.5.100/49248 dst inside:10.10.93.3/53 denied due to NAT reverse path failure

    Greg

  8. #8
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,893

    Default

    https://supportforums.cisco.com/thread/1003401

    ??

    I'm not sure why NAT is even involved here. You want the ASA to route VPN traffic into the LAN, not NAT it.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2