<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA VPN Endpoint in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083934#M892787</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to do the same thing as the original poster.  My OUTSIDE interface has an non-routable private IP address and the INSIDE interface has static public IP address.&lt;/P&gt;&lt;P&gt;I want to terminate my VPNs on the INSIDE interface, but that's not working with a fresh ASA configuration with everything enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Jan 2009 02:13:27 GMT</pubDate>
    <dc:creator>noc</dc:creator>
    <dc:date>2009-01-13T02:13:27Z</dc:date>
    <item>
      <title>ASA VPN Endpoint</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083932#M892785</link>
      <description>&lt;P&gt;I have the following setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;private IP ((non-routable) IP on the outside Interface that goes into a Router with the public (routable) IP Address) &amp;lt;-&amp;gt; ASA &amp;lt;-&amp;gt; IP DMZ (internal Interface with routable IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i want to achieve is to be able to establish vpn tunnels (road warrior, not site-to-site) to the inside Interface (routable IP) and not the outside interface (non-routable IP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this even possible ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me elaborate a bit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the idea is that the outside interface of the ASA has a private IP Address. This means that this address is not routable, so i cannot use it to connect the vpn clients to it. What i want to achieve is to be able to use the IP Address of the same ASA that resides on the DMZ Interface (which is a public/routable IP Address).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that even if i enable management-access on that interface, i have no idea if i would be able to connect to it. And since this is part of a larger ASA Production Setup, i cannot really play around with the IP Addresses (the simple way would be to subnet my dmz further and assign a small subnet on the outside interface of the asa to the border routers).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, anybody, please let me know if i can terminate vpn tunnels on the inside interface of an ASA.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083932#M892785</guid>
      <dc:creator>ardealului</dc:creator>
      <dc:date>2019-03-11T14:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Endpoint</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083933#M892786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will still have to connect to a public routeable IP address.  You can do what you want to do - you just enable the ISAKMP/IPSEC termination on the DMZ interface.  You will have to have a static NAT entry to allow this to happen - as I do not think you can perform PAT for IPSEC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 15:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083933#M892786</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-12-05T15:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Endpoint</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083934#M892787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to do the same thing as the original poster.  My OUTSIDE interface has an non-routable private IP address and the INSIDE interface has static public IP address.&lt;/P&gt;&lt;P&gt;I want to terminate my VPNs on the INSIDE interface, but that's not working with a fresh ASA configuration with everything enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 02:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083934#M892787</guid>
      <dc:creator>noc</dc:creator>
      <dc:date>2009-01-13T02:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Endpoint</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083935#M892788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry I am confused - your "outside" ip address is one of the:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10/8&lt;/P&gt;&lt;P&gt;172.16/31&lt;/P&gt;&lt;P&gt;192.168/16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;addresses ranges?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the Inside has an Internet IP address?? Errrrmmmm I would personaly reverse it, have the internet address on the outside and the internal on the inside = the normal firewall setup and configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 09:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083935#M892788</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-01-13T09:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Endpoint</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083936#M892789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your comments.  This is a special requirement, and as of now is working. &lt;/P&gt;&lt;P&gt;My question is if there is a special configuration required to accept VPNs in the INSIDE interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jorge  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jan 2009 16:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083936#M892789</guid>
      <dc:creator>noc</dc:creator>
      <dc:date>2009-01-16T16:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Endpoint</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083937#M892790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO not really - the only config change that you need to make is:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead of - crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp enable inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow VPN's to create/terminate on the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Jan 2009 09:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-endpoint/m-p/1083937#M892790</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-01-17T09:07:27Z</dc:date>
    </item>
  </channel>
</rss>

