cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1075
Views
0
Helpful
12
Replies

Access ASA that is behind a vpn tunnel and other network devices from behind another asa connected to same vpn

kylebqmacs
Level 1
Level 1

have an issue with accessing other asa's and network equipment from behind an asa that is connected to the network i need to access via vpn.  I have the asa able to access the network but for some reason am not able to.  Anyone have a solution?

12 Replies 12

Jennifer Halim
Cisco Employee
Cisco Employee

A network diagram and configuration from both ASA would help. Otherwise, we won't be able to tell why it's not working.

Below is my map.  I am trying to get the two endpoint devies to communicate with each other as well as manage the main 5510 via asdm.  I will try to post the config here in a bit.

How is the main 5510 connected?

Do you have site-to-site VPN between the 5505 and 5510?

Yes. It is ipsec site to site.

Do you mean the IPSec VPN is not UP at the moment?

What is the output of:

show cry isa sa

show cry ipsec sa

from both ASAs?

Yes the ipsec vpn is up.  I am able to access some of my network resources.  I just cant access the 5510 from the 5505 and cant access one 5505 from the other 5505.  Do i need to have reverse route enabled on the tunnel group?

You can't access the ASA itself? you mean you can't telnet/ssh/http to 5510 from 5505 LAN?

Are you trying to access it via its inside interface ip address?

Do you have "management-access inside" configured on 5510?

Do you have the 5505 LAN configured on 5510 telnet/ssh/http command?

Example:

http <5505-lan> inside

I am unable to telnet/ssh/https to 5510 from 5505 or from 5505 to 5505. 

I have the managment configured on the inside interface for all address in the range.

Also note that i have one of the 5505 setup as an any ip rule in teh 5510. So it should be able to access whatever it wants.

copy of configurations from all ASA will definitely help. It is difficult to tell what is wrong without looking at the configurations.

I am working on getting you the config.  I just have to edit out the confidential stuff.  I may be a while.  Note that i am able to access everything from my internal network just fine.  However when the 5505's ping each other i am then able to access the management features etc.  I am still unable to access the 5510 even after a ping.

I just checked the logs for the 5510.  It shows the 5505 trying to ping.  but is built and removed because of the inspect icmp command.  Do i need to add a rule for the 5505 to ping the 5510 so that the route is built?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card