I have an AnyConnect setup where I have several group policies that access several different VLAN.
One of them is called net-mgmt, and is located at GigabitEthernet1/2.301, which is part of the trunk called inside.
I have therefore set the Management Access Interface to net-mgmt.
I have under ASDM/HTTPS/Telnet/SSH set ASDM/HTTPS: net-mgmt: 192.168.101.0: 255.255.255.0
When I try to ping the device, the logs say "routing failed to locate next hop for icmp from outside 192.168.101.200/1 to net-mgmt: 192.168.101.250/0".
I have tried disabling all NAT rules without any effect. I have set AnyConnect to ignore any access rules. Pinging and connecting to all other hosts in the vlan works fine. Pinging and administering the firewall through local access works fine.
Do I need to make a NAT rule for this somehow? What would be in it, in that case? I want to be able to use ASDM and SSH from any IP within that subnet.
Radius server configuration for 802.1X
Server radius test1
Address ipv4 10.1.1.1
Server radius test2
Address ipv4 10.1.1.2
aaa group server radius TEST-gr
server name test1
server name test2
Umbrella’s cloud-delivered firewall (CDFW) is a cool features that provides Firewall Services in the Cisco Umbrella Cloud without the need to deploy on-premises firewall devices and visibility and control for internet traffic across all branch offices. To...
SymptomsDownloadable ACL (dACL) does not take effect on the IOS-XE Network Access DevicesDiagnosisCreating redirection ACL on the IOS-XE device failed to redirect the specified traffic for captive portal redirectionSolutionEnable device tracking, Below is...
Multiple Cisco Security Technologies in a single book : ASA Firepower, WSA, Umbrella, ISE and VPN with 100 percent 100 practical scenarios with 70 Labs to cover important topics of the Cisco SCOR Exam. The best part is ISE with interesting scenarios wi...