07-03-2022 10:58 AM
Hi
I have two site linked by vpn ipsec site to site.I have in each site an ASA 5525-X with ips module.I have installed my FMC in the site A in a vlan with ip 172.16.30.12/28.The ASA management interface and ips module have ip too in the same vlan.all VLAN are created on the backbone switch.and i have a default route in my backbone with gateway the ASA inside interface. I have the same configuration in site B.My problem is that the ips module in site B is in a different network with my FMC in site A.I have done the configuration but ips module can't ping FMC .I need your help to verify if this configuration can work.
Solved! Go to Solution.
07-03-2022 12:26 PM - edited 07-03-2022 12:27 PM
management-access mgmt_if <- you need this command to all management traffic through vpn.
07-03-2022 01:05 PM
I think that since the IPS is consider as management traffic so you need this command to allow it pass through tunnel.
below link how config the management traffic through vpn.
07-03-2022 12:26 PM - edited 07-03-2022 12:27 PM
management-access mgmt_if <- you need this command to all management traffic through vpn.
07-03-2022 12:45 PM
HI
If I understand correctly, this command must be executed so that the traffic from the management interfaces goes through the tunnel. And for the ips module, there will be no routing problems.
07-03-2022 01:05 PM
I think that since the IPS is consider as management traffic so you need this command to allow it pass through tunnel.
below link how config the management traffic through vpn.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide