Wednesday, July 7, 2021

ASA-AnyConnect - Possible RRI issue

Hello

I am trying to add some static routes in on my ASA to point to the other side of a P2P.

route p2p 10.1.0.0 255.255.248.0 1.1.1.1

It is erroring out for me saying the route is already in place and after checking the route table

I see the below

V 10.1.0.0 255.255.248.0 connected by VPN (advertised), outside

---

Doing my google digging here it looks like an RRI issue with our AnyConnect VPN as I see the same advertised for all of my VPN IPs in my route table (below)

V 10.2.0.50 255.255.255.255 connected by VPN (advertised), outside

V 10.2.0.51 255.255.255.255 connected by VPN (advertised), outside

V 10.2.0.57 255.255.255.255 connected by VPN (advertised), outside

V 10.2.0.61 255.255.255.255 connected by VPN (advertised), outside

V 10.2.0.66 255.255.255.255 connected by VPN (advertised), outside

V 10.2.0.68 255.255.255.255 connected by VPN (advertised), outside

We do split tunneling on our AnyConnect and is controlled by ACLs for each "VPN Group" a user connects to pulls that ACL.

Can anyone help me on how to get these routes out of the advertisement stage so that I can drop the required static in -- thanks in advance.



No comments:

Post a Comment