cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1797
Views
0
Helpful
3
Replies

Accessing ASDM via Inside interface thru site-to-site vpn

chanccmtech
Level 1
Level 1

Good Day All, 

I had a searched thru the forums looking for a very specific answer, however I can find similar topics regarding to it, but still unable to solve the issue I am currently facing. 

Looking at the above diagram, user from 192.10.10.0/24 segment wants to access ASDM of firewall 192.168.51.1 via inside interface. User from that segment is able to communicate each other without any issues, but unable to access ASDM via inside interface. What else in my configuration could I still be missing. Let's just assume I have my ACL in place already.

I have enabled the following:

management-access inside

http server enable

http 0 0 inside

http 0 0 mgmt

nat (inside,outside) source static NETWORK_OBJ_192.168.51.0_24 NETWORK_OBJ_192.168.51.0_24 destination static NETWORK_OBJ_192.10.10.0_24 NETWORK_OBJ_192.10.10.0_24 no-proxy-arp route-lookup

What else could I still be missing? Pointers would be great.

3 Replies 3

ajay chauhan
Level 7
Level 7

You should also have -

http remote_subnet outside

This article may help.

http://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/118092-configure-asa-00.html

Ajay

I have gone through that article before. Doesn't the command: 

http 0 0 inside - covers any IP accessing inside interface? 

Although by allow "http remote_subnet outside" that is pointing towards the outside interface rather than the inside interface?

Remote subnet is not local hence you should put that on outside. You can simply try that.

Ajay

Review Cisco Networking for a $25 gift card