cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1138
Views
10
Helpful
3
Replies

Permit traffic through two firewalls VPN remote access

PvCr
Level 1
Level 1

Hi everybody,

I have two firewalls Cisco ASA (5516x and 5525x).

The ASA5516X has connected one PC (192.168.50.90/24). The 5516 is the gateway (192.168.50.1/24).

The other ASA (5525X) has configured one VPN remote access (from Internet to PC:192.168.50.90).

There is a common interface between ASA5516X (192.168.50.1) and ASA5525X (192.168.50.200)

I want to communicate the VPN RA user (5525x side) to the PC:192.168.50.90 (5516x side) but I don't know how...

I configured a static route (5525X side):

route COMMON-INTF 192.168.50.90 255.255.255.255 192.168.50.1 but I can't to communicate to the PC:192.168.50.90.

I attached a drawing to illustrate the scenario.

Please help me.  Thanks.

2 Accepted Solutions

Accepted Solutions

johnd2310
Level 8
Level 8

Hi,

 

Check that on the ASA5525x you need a route for the PC network and on the AAS5516X you have a route for the VPN pool network.

 

Thanks

John

**Please rate posts you find helpful**

View solution in original post

Edwin Portillo
Spotlight
Spotlight

Friend, 

 

Verify if a static route for ASA5525X is added to the ASA5516X router through the IP address of the next hop:

 

IP route x.x.x.x x.x.x.x next_hop

 

In addition you should have a default static route of the ASA5525X to Internet :

 

Ip route 0.0.0.0 0.0.0.0 next_hop

View solution in original post

3 Replies 3

johnd2310
Level 8
Level 8

Hi,

 

Check that on the ASA5525x you need a route for the PC network and on the AAS5516X you have a route for the VPN pool network.

 

Thanks

John

**Please rate posts you find helpful**

Edwin Portillo
Spotlight
Spotlight

Friend, 

 

Verify if a static route for ASA5525X is added to the ASA5516X router through the IP address of the next hop:

 

IP route x.x.x.x x.x.x.x next_hop

 

In addition you should have a default static route of the ASA5525X to Internet :

 

Ip route 0.0.0.0 0.0.0.0 next_hop

GRANT3779
Spotlight
Spotlight

Hi There

 

Without seeing the config we can only make assumptions. Is there NAT setup on your anyconnect facing interface? If so, do you have a relevant No Nat statement for this flow? Are there ACLs?

If you can share a config it would help.

Review Cisco Networking for a $25 gift card