<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cannot access asdm over L2L VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373416#M960932</link>
    <description>&lt;P&gt;We have L2L VPN between 2 sites working without any issue, except we are not able to access ssh/asdm of remote ASA (DR) from local LAN of local ASA (HQ).&lt;/P&gt;
&lt;P&gt;We have followed this cisco document&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/118092-configure-asa-00.html#anc7" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/118092-configure-asa-00.html#anc7&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;we have&lt;/P&gt;
&lt;P&gt;1. route-lookup for No-NAT subnets (local and remote ASA)&lt;/P&gt;
&lt;P&gt;2. management-access inside ( remote ASA)&lt;/P&gt;
&lt;P&gt;3. SSH/HTTP allowed on inside interface (remote ASA)&lt;/P&gt;
&lt;P&gt;4. SSH/HTTP allowed on outside interface (remote ASA)&lt;/P&gt;
&lt;P&gt;5. Routing is okay&lt;/P&gt;
&lt;P&gt;6. We can see packet leaves local ASA and hits remote ASA (ASDM monitoring).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your input is highly appreciated and look forward for positive response.&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Ahmed...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:40:17 GMT</pubDate>
    <dc:creator>ahmed.gadi</dc:creator>
    <dc:date>2020-02-21T15:40:17Z</dc:date>
    <item>
      <title>cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373416#M960932</link>
      <description>&lt;P&gt;We have L2L VPN between 2 sites working without any issue, except we are not able to access ssh/asdm of remote ASA (DR) from local LAN of local ASA (HQ).&lt;/P&gt;
&lt;P&gt;We have followed this cisco document&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/118092-configure-asa-00.html#anc7" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/118092-configure-asa-00.html#anc7&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;we have&lt;/P&gt;
&lt;P&gt;1. route-lookup for No-NAT subnets (local and remote ASA)&lt;/P&gt;
&lt;P&gt;2. management-access inside ( remote ASA)&lt;/P&gt;
&lt;P&gt;3. SSH/HTTP allowed on inside interface (remote ASA)&lt;/P&gt;
&lt;P&gt;4. SSH/HTTP allowed on outside interface (remote ASA)&lt;/P&gt;
&lt;P&gt;5. Routing is okay&lt;/P&gt;
&lt;P&gt;6. We can see packet leaves local ASA and hits remote ASA (ASDM monitoring).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your input is highly appreciated and look forward for positive response.&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Ahmed...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373416#M960932</guid>
      <dc:creator>ahmed.gadi</dc:creator>
      <dc:date>2020-02-21T15:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373432#M960933</link>
      <description>&lt;P&gt;Have you included the ASA inside interface that you are trying to connect to in the crypto ACL?&amp;nbsp; Would help if you posted the full running configuration for both sides of the tunnel.&amp;nbsp; Remember to remove any public IPs, usernames, passwords, and hostname of the devices.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 07:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373432#M960933</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-26T07:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373439#M960934</link>
      <description>&lt;P&gt;Yes included, I will post the desired config soon&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 07:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373439#M960934</guid>
      <dc:creator>ahmed.gadi</dc:creator>
      <dc:date>2018-04-26T07:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373506#M960935</link>
      <description>Interesting one; can you ping it at least? &lt;BR /&gt;I would run :capture type asp-drop match ip host ...".&lt;BR /&gt;&lt;BR /&gt;I would also double check NAT config on both sides.</description>
      <pubDate>Thu, 26 Apr 2018 08:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373506#M960935</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-04-26T08:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373534#M960936</link>
      <description>&lt;P&gt;Please check attached desired config&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 09:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373534#M960936</guid>
      <dc:creator>ahmed.gadi</dc:creator>
      <dc:date>2018-04-26T09:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373540#M960937</link>
      <description>&lt;P&gt;Ping is blocked in whole path (Cisco ASA, CheckPoint Firewall and Perimeter router).&lt;/P&gt;
&lt;P&gt;I have not done this&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;capture type asp-drop match ip host ...".&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 09:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373540#M960937</guid>
      <dc:creator>ahmed.gadi</dc:creator>
      <dc:date>2018-04-26T09:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373569#M960938</link>
      <description>&lt;P&gt;This is just partial configuration please provide a full configuration of the two ASAs (remember to remove public IPs, usernames, passwords)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or at least provide us with all Crypto configuration, NAT configuration, routing configuration, and information on which IP you are trying to access the ASA from.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 09:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373569#M960938</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-26T09:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373990#M960939</link>
      <description>Config is good - still capture asp-drop can tell you if something "unexpected" takes place.&lt;BR /&gt;You can also run a capture based on an ACL place on the inside interface and see how 'what you can see'</description>
      <pubDate>Thu, 26 Apr 2018 19:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3373990#M960939</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-04-26T19:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3374010#M961028</link>
      <description>&lt;P&gt;Is this by any chance an ASA5506 configured with BVI?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 19:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3374010#M961028</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-26T19:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3374653#M961029</link>
      <description>&lt;P&gt;After capturing packets and packet tracer, i found that the traffic was hitting different natting which did not have route lookup command, so after rectifying natting, &amp;nbsp;asdm was accessible.&lt;/P&gt;
&lt;P&gt;thanks for your input.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 18:32:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3374653#M961029</guid>
      <dc:creator>ahmed.gadi</dc:creator>
      <dc:date>2018-04-27T18:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access asdm over L2L VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3374840#M961030</link>
      <description>&lt;P&gt;This is why I keep asking for the full running configuration of the ASA as there might be some configuration that people think is not relevant but it actually is.&lt;/P&gt;
&lt;P&gt;Glad you found the solution though&lt;/P&gt;</description>
      <pubDate>Sat, 28 Apr 2018 07:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-asdm-over-l2l-vpn/m-p/3374840#M961030</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-28T07:44:41Z</dc:date>
    </item>
  </channel>
</rss>

