<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't connect ASDM from remote site. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3897348#M26903</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;I have the more detail to update my current connection show as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Client ----&amp;gt; L3 switch ----&amp;gt; Checkpoint Firewall x2 (Clustered) ----&amp;gt;Cisco ASA----&amp;gt; Network&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I've use the wiresharsk captured the traffic&amp;nbsp; between Checkpoint and ASA I have found some thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the ASA with 9.6(1) firmware (this version is working as expected)&lt;/P&gt;&lt;P&gt;Checkpoint will forward traffic to ASA with it real physical MAC address as source and ASA reply with the CheckPoint real MAC address as destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the ASA with 9.9(2) firmware (this version is not working)&lt;/P&gt;&lt;P&gt;Checkpoint will forward traffic to ASA with it real physical MAC address as source and ASA reply with the CheckPoint Virtual MAC address as destination. That is why the communication cannot established.&lt;/P&gt;&lt;P&gt;So How can I do on the configuration of&amp;nbsp;9.9(2) firmware ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2019 08:04:26 GMT</pubDate>
    <dc:creator>msompong1</dc:creator>
    <dc:date>2019-07-25T08:04:26Z</dc:date>
    <item>
      <title>Can't connect ASDM from remote site.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3891533#M26899</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I've setup the Cisco ASA 5506x firewall with the simple connection.&lt;/P&gt;&lt;P&gt;- outsite interface connect to internet.&lt;/P&gt;&lt;P&gt;- inside interface connect to my production.&lt;/P&gt;&lt;P&gt;- P2P interface connect to the existing network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is I can't access the ASDM from network behind the P2P link , I've found the log in ASA about my source IP and the service 443 but ASDM client show "Unable to lunch device manager from xx.xx.xx.xx"&lt;/P&gt;&lt;P&gt;But when I tried from inside network the&amp;nbsp;ASDM&amp;nbsp; can lunch as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've enable the source network for access ASA as below.&lt;/P&gt;&lt;P&gt;http server enable&lt;BR /&gt;http 192.168.140.0 255.255.255.0 inside&lt;BR /&gt;http 10.196.0.0 255.255.0.0 P2P&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the routing also have&amp;nbsp;&lt;/P&gt;&lt;P&gt;route P2P 10.196.0.0 255.255.0.0 10.196.7.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help to advice and thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 02:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3891533#M26899</guid>
      <dc:creator>msompong1</dc:creator>
      <dc:date>2019-07-17T02:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect ASDM from remote site.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3891545#M26901</link>
      <description>&lt;P&gt;Is it possible that your traffic arriving via the P2P link is being NATted along the way? You can test this by temporarily changing your current:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;http 10.196.0.0 255.255.0.0 P2P&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;to&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;http 0.0.0.0 0.0.0.0 P2P&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If it works with that then check your ASA/ASDM logs to see the actual incoming address of the connections and update the http statement accordingly.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 03:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3891545#M26901</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-17T03:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect ASDM from remote site.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3891669#M26902</link>
      <description>Hi There, I had a very similar issue recently but asdm access was an issue across a 4G WAN link. Out of interest, can you SSH to the ASA across the P2P?&lt;BR /&gt;My problem was MTU/Fragmentation or lack of. I had to add tcp miss-adjust on the WAN interfaces. I only knew this was the issue after running some packet captures to see what was going on.&lt;BR /&gt;May be unrelated to your issue but thought I would make you aware.</description>
      <pubDate>Wed, 17 Jul 2019 07:48:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3891669#M26902</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-07-17T07:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect ASDM from remote site.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3897348#M26903</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;I have the more detail to update my current connection show as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Client ----&amp;gt; L3 switch ----&amp;gt; Checkpoint Firewall x2 (Clustered) ----&amp;gt;Cisco ASA----&amp;gt; Network&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I've use the wiresharsk captured the traffic&amp;nbsp; between Checkpoint and ASA I have found some thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the ASA with 9.6(1) firmware (this version is working as expected)&lt;/P&gt;&lt;P&gt;Checkpoint will forward traffic to ASA with it real physical MAC address as source and ASA reply with the CheckPoint real MAC address as destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the ASA with 9.9(2) firmware (this version is not working)&lt;/P&gt;&lt;P&gt;Checkpoint will forward traffic to ASA with it real physical MAC address as source and ASA reply with the CheckPoint Virtual MAC address as destination. That is why the communication cannot established.&lt;/P&gt;&lt;P&gt;So How can I do on the configuration of&amp;nbsp;9.9(2) firmware ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 08:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3897348#M26903</guid>
      <dc:creator>msompong1</dc:creator>
      <dc:date>2019-07-25T08:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect ASDM from remote site.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3897504#M26904</link>
      <description>&lt;P&gt;From your latest description and the analysis you've done, this sounds like a bug. Are you running the latest interim release of 9.9(2)?&lt;/P&gt;
&lt;P&gt;That would currently be 9.9(2)52 found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/286283326/type/280775065/release/9.9.2%20Interim" target="_blank"&gt;https://software.cisco.com/download/home/286283326/type/280775065/release/9.9.2%20Interim&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you are already running the latest interim then I would advise opening a TAC case.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 11:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-asdm-from-remote-site/m-p/3897504#M26904</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-25T11:23:31Z</dc:date>
    </item>
  </channel>
</rss>

