Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.400 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-05-2008, 04:59 PM
Moderator
 
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 783
Default [FEATURE] [7.360] Cisco VPN - ALL traffic goes through ipsec..

Not ideal, but the the client is routing all traffic including internet over the vpn, because it has a route for 0.0.0.0 0.0.0.0 . We should be able to select if possible which routes go over the tunnel, just like with the SSL.
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.
  #2 (permalink)  
Old 12-08-2008, 09:06 AM
Moderator
 
Join Date: Nov 2007
Location: Karlsruhe, Germany
Posts: 78
Default

That's actually a limitation - if you want to call it that - of the Cisco VPN Client. During IKE Phase 2 it proposes 0.0.0.0/0 as the remote network. I think there's no way around it, sorry.
  #3 (permalink)  
Old 12-08-2008, 11:57 AM
gnujuba's Avatar
Senior Member
 
Join Date: Jan 2003
Posts: 186
Default

Quote:
Originally Posted by ReD-MaN View Post
Not ideal, but the the client is routing all traffic including internet over the vpn, because it has a route for 0.0.0.0 0.0.0.0 . We should be able to select if possible which routes go over the tunnel, just like with the SSL.
what you mean is called "split tunneling" and can be configured on cisco pix/asa/vpn3k just by defining what network to tunnel(*).

what about your ipsec config on the astaro? what networks did you choose as remote networks (dont know if this is the right word for the networks you want to tunnel).

* http://www.cisco.com/en/US/products/...80702999.shtml

Last edited by gnujuba; 12-08-2008 at 11:59 AM.
  #4 (permalink)  
Old 12-08-2008, 12:52 PM
Moderator
 
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 783
Default

Yes it is split-tunneling, which I have enabled on all my ASA firewalls at work.

Here is a screenshot showing how I only secure routes for the remote networks, and interntet still goes out locally, when I connect to Cisco firewalls.
Attached Images
File Type: png routes.png (20.4 KB, 17 views)
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.

Last edited by ReD-MaN; 12-08-2008 at 01:30 PM.
  #5 (permalink)  
Old 12-08-2008, 01:10 PM
gnujuba's Avatar
Senior Member
 
Join Date: Jan 2003
Posts: 186
Default

Quote:
Originally Posted by ReD-MaN View Post
Yes it is split-tunneling, which I have enabled on all my ASA firewalls at work.

Here is a screenshot showing how I only secure routes for the remote networks, and interntet still goes out locally.
this means its working and you can select which routes go through the tunnel and which not?
  #6 (permalink)  
Old 12-08-2008, 01:30 PM
Moderator
 
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 783
Default

Quote:
Originally Posted by gnujuba View Post
this means its working and you can select which routes go through the tunnel and which not?
No, that screenshot is showing how it works on my Cisco gear. When I use the same client to connect to my beta ASG, the only secured network is 0.0.0.0/0.0.0.0 .
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.
  #7 (permalink)  
Old 12-08-2008, 01:31 PM
Moderator
 
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 783
Default

Quote:
Originally Posted by gnujuba View Post
what you mean is called "split tunneling" and can be configured on cisco pix/asa/vpn3k just by defining what network to tunnel(*).

what about your ipsec config on the astaro? what networks did you choose as remote networks (dont know if this is the right word for the networks you want to tunnel).

* ASA/PIX: Allow Split Tunneling for VPN Clients on the ASA Configuration Example - Cisco Systems
I selected my primary internal network, as well as a few internal routed networks.
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.
  #8 (permalink)  
Old 12-09-2008, 01:13 PM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,173
Default

Hi, it seems that using split tunneling requires a Cisco ASA Access Server. We'll look into making this available in the future.
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
  #9 (permalink)  
Old 12-09-2008, 02:06 PM
Moderator
 
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 783
Default

Quote:
Originally Posted by tom View Post
Hi, it seems that using split tunneling requires a Cisco ASA Access Server. We'll look into making this available in the future.
This works on my older PIX 520 firewalls too running PIX OS 6.3.4.. and they have been EOL for a while now

Oh well, the whole Cisco VPN support is awesome regardless!!!
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.
  #10 (permalink)  
Old 12-09-2008, 02:52 PM
gnujuba's Avatar
Senior Member
 
Join Date: Jan 2003
Posts: 186
Default

Quote:
Originally Posted by ReD-MaN View Post
Oh well, the whole Cisco VPN support is awesome regardless!!!
I think its cool too - but a bit late I.e. Cisco will not release a 64bit Vista version of their IPSec VPN Client.
They are moving towards the Any-Connect Client (which supports only SSL VPN at the moment).

But anyway, I really like what I have seen so far from this beta... https scanning, ssl site2site etc...
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:20 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.