<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to access asacx over L2L VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536697#M206308</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to access the asacx module installed on a remote ASA 5525 over a L2L VPN tunnel. When attempting to access the asacx module I see the following in the ASA logs: &amp;nbsp; The IP address of the asacx module is 192.168.148.3. The IP address of the management interface on the ASA is 192.168.148.2.&lt;/P&gt;&lt;P&gt;&amp;lt;172&amp;gt;%ASA-4-418001: Through-the-device packet to/from management-only network is denied: tcp src outside:192.168.50.112/58002 dst management:192.168.148.3/443&lt;/P&gt;&lt;P&gt;Is there anyway to get around it this? Is there a possible way to route back to the management network through the router on the other side?&lt;/P&gt;&lt;P&gt;I think if I could delete the connected route for the 192.168.148.0 network I could just route through the inside interface and then back to the management. &amp;nbsp;How do you all access your asacx's remotely?&lt;/P&gt;&lt;P&gt;Thank you in advance for any help that you can provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:53:01 GMT</pubDate>
    <dc:creator>natec</dc:creator>
    <dc:date>2019-03-12T04:53:01Z</dc:date>
    <item>
      <title>How to access asacx over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536697#M206308</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to access the asacx module installed on a remote ASA 5525 over a L2L VPN tunnel. When attempting to access the asacx module I see the following in the ASA logs: &amp;nbsp; The IP address of the asacx module is 192.168.148.3. The IP address of the management interface on the ASA is 192.168.148.2.&lt;/P&gt;&lt;P&gt;&amp;lt;172&amp;gt;%ASA-4-418001: Through-the-device packet to/from management-only network is denied: tcp src outside:192.168.50.112/58002 dst management:192.168.148.3/443&lt;/P&gt;&lt;P&gt;Is there anyway to get around it this? Is there a possible way to route back to the management network through the router on the other side?&lt;/P&gt;&lt;P&gt;I think if I could delete the connected route for the 192.168.148.0 network I could just route through the inside interface and then back to the management. &amp;nbsp;How do you all access your asacx's remotely?&lt;/P&gt;&lt;P&gt;Thank you in advance for any help that you can provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536697#M206308</guid>
      <dc:creator>natec</dc:creator>
      <dc:date>2019-03-12T04:53:01Z</dc:date>
    </item>
    <item>
      <title>Hi,This is expected as the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536698#M206309</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is expected as the management interface will never allow any through traffic. You would have to route this traffic through a different interface and probably the Inside interface of the ASA device.&lt;/P&gt;&lt;P&gt;Put a static route to the inside interface for the CX management IP and that should resolve this issue for you.&lt;/P&gt;&lt;P&gt;Check this Doc for more information[Scenario 4]:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/ips-sensor-software-version-71/113690-ips-config-mod-00.html&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 02:01:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536698#M206309</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-10-09T02:01:52Z</dc:date>
    </item>
    <item>
      <title>Vibhor's answer is the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536699#M206310</link>
      <description>&lt;P&gt;Vibhor's answer is the correct approach.&amp;nbsp;I have used it successfully myself.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 03:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536699#M206310</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-09T03:44:17Z</dc:date>
    </item>
    <item>
      <title>Thank you Vibhor and Marvin</title>
      <link>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536700#M206311</link>
      <description>&lt;P&gt;Thank you Vibhor and Marvin,&lt;/P&gt;&lt;P&gt;For completeness I will also add that if you have an IP address on the management interface of the ASA you will have to take it off or it will show a connected route which will be weighted lower than the static. Once I put the static in and took the IP address off of the management interface I was able to access the asacx module.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 21:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536700#M206311</guid>
      <dc:creator>natec</dc:creator>
      <dc:date>2014-10-09T21:17:42Z</dc:date>
    </item>
    <item>
      <title>You don't need to remove the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536701#M206312</link>
      <description>&lt;P&gt;You don't need to remove the ASA management IP as the connected routes on that interface are only the /32 of the ASA management address itself and the subnet to which it belongs, be it a /24 or whatever.&lt;/P&gt;&lt;P&gt;Your static route for the CX management should be a /32 route for that address. Thus the longest prefix match will choose that static route despite it belonging to the same subnet as the ASA management interface.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 22:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-access-asacx-over-l2l-vpn/m-p/2536701#M206312</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-09T22:11:07Z</dc:date>
    </item>
  </channel>
</rss>

