cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
552
Views
5
Helpful
2
Replies

ASA management interface

mohammad saeed
Level 5
Level 5

Hi Guys,

 

I have one ASA and I want to access to ASA management interface through my inside network, can I do that instead of connect dedicated cable from Management interface to PC?

 

 

Thanks for all

 

Mohammad Saeed

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

You can, but it is challenging to be on a remote subnet. The problem is that as of the current ASA software (i.e version 9.4 or earlier) there is only a single routing table for the ASA.

So it can be challenging to setup routes telling the ASA to reach a given subnet using the management interface when that same subnet may need its data to flow in and out of the inside interface for the non-management functions of the ASA.

You also need to tell the ASA to allow management from subnets not on the same subnet as the management interface. 

nspasov
Cisco Employee
Cisco Employee

Marvin is spot on! (+5). I would also suggest that you either use a dedicated cable and subnet for the management interface or allow management traffic via the "inside" interface. Be careful as Marvin pointed out there is only a single routing table and assigning an IP address from the same range on your management and Inside interface can cause you to actually drop traffic. I speak from experience...or lack of :)

 

Thank you for rating helpful posts!

Thank you for rating helpful posts!
Review Cisco Networking for a $25 gift card