Remote access to a pc with AnyconnectVPN

Solved
Rm2JulianRV
Comes here often

Remote access to a pc with AnyconnectVPN

Hello, I need to connect to a remote PC, it was fine until I enable this configuration:

"Client Routing / only send traffic to going to these destinations"  and

"Dynamic Client Routing / Only send traffic going to these destinations

 

This configuration has some CIDR and Hostname.

Screenshot 2023-03-31 at 8.34.48 AM.png

 I wanna know if there is something I need to configure to allow me to connect remotely.

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

What subnet is the PC on? Is any of these added in the config?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

4 Replies 4
alemabrahao
Kind of a big deal
Kind of a big deal

What subnet is the PC on? Is any of these added in the config?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

I  add the subnet (172.16.6.0/24) and still doesn't work.

Take a look at this:

 

 

Client routing: This is used to specify full or split-tunnel rules pushed to the AnyConnect client device. You can send all traffic through VPN, all traffic except traffic going to specific destinations, or only send traffic going to specific destinations.

Dynamic Client routing: This is used to specify full or split-tunnel rules pushed to the AnyConnect client device by hostname. For more details see Dynamic Client routing

 

Local LAN access

Local LAN access may be desired when Full tunneling is configured (Send all traffic through VPN), but users still require the ability to communicate with their local network. For example, a client that is allowed local LAN access while connected to the MX in full tunnel mode is able to print to a local printer at home, while other traffic flows through the tunnel.

To enable local LAN access, two things need to be done. Local LAN access will not work if both conditions are not satisfied.

1. Configure the MX: Select "Send all traffic except traffic going to these destinations" option on the Dashboard and configure a 0.0.0.0/32 route. This will cause the AnyConnect client to automatically exclude traffic destined for the user's local network from going over the tunnel.

 

Check the route details on Anyconnect:

 

alemabrahao_0-1680271141281.png

Full doc: https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Hello again, sorry for the late response, I have finally been able to configure that. It still does not work, we have a split tunnel, and we cannot use (1)"Send all traffic except traffic going to these destinations" only (2)"Only send traffic going to these destinationsScreenshot 2023-04-12 094019.png"

 

Thanks.

Get notified when there are additional replies to this discussion.