<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access ASDM from different interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841970#M1100816</link>
    <description>&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; mention there is two plane in ASA&amp;nbsp;&lt;BR /&gt;DATA PLANE and MGMT PLANE&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it separate so access via test01 for subnet of test02 is not pass through the DATA PLANE and access failed&amp;nbsp;&lt;BR /&gt;you need to specify subnet that direct connect to interface use in command or use 0.0.0.0 (cisco not recommend this it risky)&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 17:38:58 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-05-24T17:38:58Z</dc:date>
    <item>
      <title>Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841949#M1100809</link>
      <description>&lt;P&gt;Hello together,&lt;/P&gt;&lt;P&gt;I am trying to access our ASA via ASDM from another Interface than the Management Interface.&lt;BR /&gt;I have multiple subinterfaces and I would like to access from one Host (Host A) behind Interface "test01" to the ASA via ASDM:&lt;/P&gt;&lt;P&gt;GigabitEthernet0/1.1&lt;BR /&gt;vlan 22&lt;BR /&gt;nameif test01&lt;BR /&gt;security-level 92&lt;BR /&gt;ip address 192.168.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;GigabitEthernet0/1.2&lt;BR /&gt;vlan 33&lt;BR /&gt;nameif test02&lt;BR /&gt;security level 95&lt;BR /&gt;ip address 192.168.2.254 255.255.255.0&lt;/P&gt;&lt;P&gt;If opening ASDM from Host A (192.168.1.5) and trying to connect to 192.168.2.254 it does not work.&lt;BR /&gt;In the logs I can see that the ASA in unable to locate the egress Interface. If simulating the traffic via packet tracer it&lt;BR /&gt;says "no route to host". But the interfaces are directly connected.&lt;/P&gt;&lt;P&gt;I have already tried to grant management access via:&lt;/P&gt;&lt;P&gt;http 192.168.1.5 255.255.255.255 test02&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Am I missing here something or is this not possible?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA Version 9.12(4)47&lt;/P&gt;&lt;P&gt;ASDM Version 7.20(1)23&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841949#M1100809</guid>
      <dc:creator>jensscheuvens</dc:creator>
      <dc:date>2023-05-24T14:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841951#M1100810</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/151372"&gt;@jensscheuvens&lt;/a&gt; if you are connected behind test01 interface of the ASA you can only connect using SSH, HTTP (ASDM) etc to the closest interface (test01), not a far interface (test02) - thats' by design. The only exception to that if mgmt was over a VPN.&lt;/P&gt;
&lt;P&gt;FYI, packet-tracer if for traffic "through" the ASA, not "to" the ASA so is not representative.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841951#M1100810</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-24T14:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841953#M1100811</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Use&amp;nbsp;http 0.0.0.0 0.0.0.0 &lt;SPAN&gt;test01&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841953#M1100811</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-05-24T14:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841955#M1100812</link>
      <description>&lt;P&gt;check comment above&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 08:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841955#M1100812</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-25T08:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841968#M1100814</link>
      <description>&lt;P&gt;Thanks for your answer. It is the same when trying to access the device via SSH from 192.168.1.5 "failed to locate egress interface"&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841968#M1100814</guid>
      <dc:creator>jensscheuvens</dc:creator>
      <dc:date>2023-05-24T14:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841969#M1100815</link>
      <description>&lt;P&gt;http 192.168.1.5 255.255.255.255 test01 &amp;lt;&amp;lt;- if you want to access via test01 subnet&lt;/P&gt;&lt;P&gt;Yes I would like to access from 192.168.1.5 via ASDM to 192.168.2.254.&lt;/P&gt;&lt;P&gt;I tested both but with the same result&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841969#M1100815</guid>
      <dc:creator>jensscheuvens</dc:creator>
      <dc:date>2023-05-24T14:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841970#M1100816</link>
      <description>&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; mention there is two plane in ASA&amp;nbsp;&lt;BR /&gt;DATA PLANE and MGMT PLANE&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it separate so access via test01 for subnet of test02 is not pass through the DATA PLANE and access failed&amp;nbsp;&lt;BR /&gt;you need to specify subnet that direct connect to interface use in command or use 0.0.0.0 (cisco not recommend this it risky)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 17:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841970#M1100816</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-24T17:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841979#M1100817</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/151372"&gt;@jensscheuvens&lt;/a&gt; but your configuration is incorrect if connecting from 192.168.1.5, the source interface is test01.&lt;/P&gt;
&lt;P&gt;http 192.168.1.5 255.255.255.255 test0&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;...then connect to 129.168.1.254.&lt;/P&gt;
&lt;P&gt;As I mentioned you cannot be connected behind test01 interface and connect to test02 interface.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841979#M1100817</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-24T14:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841980#M1100818</link>
      <description>&lt;P&gt;check above&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 08:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841980#M1100818</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-25T08:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841983#M1100819</link>
      <description>&lt;P&gt;This is the command you need to configure if you access from 192.168.1.5&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;asdm image flash:asdm-openjre-7xx-1xx.bin
!
aaa authentication http console LOCAL
aaa authorization exec LOCAL auto-enable
aaa authentication login-history
!
http server enable
http server idle-timeout 60
https 192.168.1.5 255.255.255.255  test01&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 15:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841983#M1100819</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2023-05-24T15:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841988#M1100820</link>
      <description>&lt;P&gt;His interface IP is .254 not .5&amp;nbsp;&lt;BR /&gt;just want to notice you&amp;nbsp;&lt;BR /&gt;thanks&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 15:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4841988#M1100820</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-24T15:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842556#M1100848</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; have configured&amp;nbsp;http 192.168.1.5 255.255.255.255 test01.&amp;nbsp;&lt;BR /&gt;It was a mistake that I wrote above test02.&lt;/P&gt;&lt;P&gt;Ok thanks for your explanations and it is now clear to me.&lt;/P&gt;&lt;P&gt;One question which came to my mind yesterday:&lt;/P&gt;&lt;P&gt;If performing a NAT like:&lt;/P&gt;&lt;P&gt;SRC INT:&amp;nbsp;test01&lt;BR /&gt;SRC: 192.168.1.5&lt;/P&gt;&lt;P&gt;DST INT:&amp;nbsp;test02&lt;BR /&gt;SRC: 192.168.2.254&lt;/P&gt;&lt;P&gt;would that work?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 07:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842556#M1100848</guid>
      <dc:creator>jensscheuvens</dc:creator>
      <dc:date>2023-05-25T07:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842629#M1100849</link>
      <description>&lt;P&gt;192.168.2.254 is the IP address of test02 which is Firewall interface GigabitEthernet0/1.2.&lt;/P&gt;
&lt;P&gt;unless you do something like this&lt;/P&gt;
&lt;P&gt;object network Real-IP-test01&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.1.5&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;nat (test01,test02) source static Real-IP-test01 Interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;object network Real-IP2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.2.100&lt;/P&gt;
&lt;P&gt;nat(test01,test02) source static Real-IP-test01 Real-IP2&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 08:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842629#M1100849</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2023-05-25T08:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842631#M1100850</link>
      <description>&lt;P&gt;Thank you every one. The thread can be closed then&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 08:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842631#M1100850</guid>
      <dc:creator>jensscheuvens</dc:creator>
      <dc:date>2023-05-25T08:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Access ASDM from different interface</title>
      <link>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842634#M1100851</link>
      <description>&lt;P&gt;You are so welcome&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 08:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-asdm-from-different-interface/m-p/4842634#M1100851</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-25T08:40:44Z</dc:date>
    </item>
  </channel>
</rss>

