<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN on Perimeter Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224606#M834997</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Through webvpn you can access any systems inside your network that provides network management , whether web-based management apps or rdp to management stations  you can simply access those apps from within Webvpn session. Perhaps with Anyconnect SSL client you may be able to manage devices from the connected source, if you do need to directly manage remote network  better to stablish a L2L vpn to manage remote network through permanent ipsec tunnel.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 07 Jun 2009 22:48:36 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2009-06-07T22:48:36Z</dc:date>
    <item>
      <title>Remote Access VPN on Perimeter Firewall</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224603#M834994</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a pair of ASA 5520 as our commercial web portal perimeter firewall. Is it feasible to configure remote access VPN (for remote management) on the same set of firewalls or is it better to use a separate firewall for this purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would there be any performance degradation...(max would be 5 users at any point in time). &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224603#M834994</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2019-03-11T15:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN on Perimeter Firewall</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224604#M834995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can, when you say remote management are you referring to management of the firewall? if so you have many other options if it is just for remote management of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- You can configure RA VPN  and manage the firewall or any other resources inside your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0r&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- If it is just for firewall management and nothing else you can simply allow the access from source IP  and destination of the firewall outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if user1  with public ip of 20.20.20.20  you can allow management to the firewall exclusivaly from that IP as:&lt;/P&gt;&lt;P&gt;This scenario would be for a user who has permanent static IP, would not recommend this scenario if user changes public IP. The downside in this is the user is bound to manage the firewall from that only Ip address as suppose to using Cisco VPN client RA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#http 20.20.20.20 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;asa(config)#ssh 20.20.20.20 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3- You can configure SSL Webvpn for those users, there is no client needed to be installed on the 5 users machines ,  through ssl webvpn you can then allow them access to any system to manage the firewall. This scenario provide beter mobility as ssl vpn just requires web browser that supports SSL which most browsers do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Would there be any performance degradation...(max would be 5 users at any point in time).&lt;/B&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jun 2009 17:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224604#M834995</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-06-06T17:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN on Perimeter Firewall</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224605#M834996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the servers and network devices be managed over SSL WebVPN. If so, how can it be achieved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Jun 2009 09:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224605#M834996</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2009-06-07T09:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN on Perimeter Firewall</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224606#M834997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Through webvpn you can access any systems inside your network that provides network management , whether web-based management apps or rdp to management stations  you can simply access those apps from within Webvpn session. Perhaps with Anyconnect SSL client you may be able to manage devices from the connected source, if you do need to directly manage remote network  better to stablish a L2L vpn to manage remote network through permanent ipsec tunnel.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Jun 2009 22:48:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-on-perimeter-firewall/m-p/1224606#M834997</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-06-07T22:48:36Z</dc:date>
    </item>
  </channel>
</rss>

