10-04-2012 06:23 AM - edited 03-11-2019 05:04 PM
have an issue with accessing other asa's and network equipment from behind an asa that is connected to the network i need to access via vpn. I have the asa able to access the network but for some reason am not able to. Anyone have a solution?
10-04-2012 06:27 AM
A network diagram and configuration from both ASA would help. Otherwise, we won't be able to tell why it's not working.
10-04-2012 06:36 AM
Below is my map. I am trying to get the two endpoint devies to communicate with each other as well as manage the main 5510 via asdm. I will try to post the config here in a bit.
10-04-2012 06:51 AM
How is the main 5510 connected?
Do you have site-to-site VPN between the 5505 and 5510?
10-04-2012 06:52 AM
Yes. It is ipsec site to site.
10-04-2012 06:54 AM
Do you mean the IPSec VPN is not UP at the moment?
What is the output of:
show cry isa sa
show cry ipsec sa
from both ASAs?
10-04-2012 06:55 AM
Yes the ipsec vpn is up. I am able to access some of my network resources. I just cant access the 5510 from the 5505 and cant access one 5505 from the other 5505. Do i need to have reverse route enabled on the tunnel group?
10-04-2012 07:01 AM
You can't access the ASA itself? you mean you can't telnet/ssh/http to 5510 from 5505 LAN?
Are you trying to access it via its inside interface ip address?
Do you have "management-access inside" configured on 5510?
Do you have the 5505 LAN configured on 5510 telnet/ssh/http command?
Example:
http <5505-lan>
10-04-2012 07:05 AM
I am unable to telnet/ssh/https to 5510 from 5505 or from 5505 to 5505.
I have the managment configured on the inside interface for all address in the range.
10-04-2012 07:15 AM
Also note that i have one of the 5505 setup as an any ip rule in teh 5510. So it should be able to access whatever it wants.
10-04-2012 07:20 AM
copy of configurations from all ASA will definitely help. It is difficult to tell what is wrong without looking at the configurations.
10-04-2012 07:42 AM
I am working on getting you the config. I just have to edit out the confidential stuff. I may be a while. Note that i am able to access everything from my internal network just fine. However when the 5505's ping each other i am then able to access the management features etc. I am still unable to access the 5510 even after a ping.
10-04-2012 07:47 AM
I just checked the logs for the 5510. It shows the 5505 trying to ping. but is built and removed because of the inspect icmp command. Do i need to add a rule for the 5505 to ping the 5510 so that the route is built?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide