cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
980
Views
0
Helpful
5
Replies

DMZ to VPN (Outside)

NetworkGuy!
Level 1
Level 1

Hi

 

My setup is at follows

 

Inside-------Firewall

                           |

                           |

                       Guest DMZ

 

Now if i wanted to VPN (anyconnect) from Guest DMZ to Firewall on the outside public address - is it possible? we have only 1 publi address and same address is used for NATting Inside and Guest networks

 

I have enabled same-security intra interface and does not work

5 Replies 5

Abheesh Kumar
VIP Alumni
VIP Alumni
Hi,
So you would like to enable remote access vpn (anyconnect ) for Guest DMZ users right...?

I am not sure if I understand your question but I want Guest DMZ users to be able to anyconnect back in to the public interface, got it?

So from public Internet you need to connect to Guest DMZ network via anyconnect. I think this is what you are planning to achieve.
This can be possible by enabling remote access vpn on OUTSIDE interface and allow the VPN-Pool(anyconnect Pool) to access Guest DMZ subnet.

HTH
Abheesh

No! I need to access anyconnect from DMZ Guest network 

 

basically imagine the dmz subnet is 192.168.1.0/24 and when it leaves the firewall its NATd to 102.1.1.1 - I need users from 192.168.1.0/24 to connect to anyconnect on 102.1.1.1 (outside interface of firewall where anyconnect is running)

Hi,
You cannot do anyconnect from DMZ to your own outside interface.

HTH
Abheesh
Review Cisco Networking products for a $25 gift card