cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2269
Views
0
Helpful
6
Replies

Unable to ssh to the inside interface of ASA over site-to-site VPN

shaun barrs
Level 1
Level 1

Hi All,

I am having a problem accessing a couple of newly setup ASA's via the inside interface over a site-to-site VPN.  I can SSH etc to nodes either side of the ASA no problem and from the ASA to the Monitoring Server at the other end of the tunnel that I want to model the ASA's on but for the life of me I can't seem to be able to manage them from the inside interface.

Snippet of relevant config below.  VPN is all up and working correctly so have left that part of the config out for now.

no ssh stricthostkeycheck
ssh ***.***.***.*** 255.255.255.0 Outside
ssh 0.0.0.0 0.0.0.0 Inside
ssh 10.0.0.0 255.0.0.0 MGT
ssh timeout 60
ssh key-exchange group dh-group1-sha1
console timeout 0
management-access Inside

Any help would be much appreciated.

1 Accepted Solution

Accepted Solutions

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

Are you able to ping the inside IP ?

If you are using a NAT statement for the VPN traffic please add route-lookup keyword to it and then check.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

View solution in original post

6 Replies 6

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

Are you able to ping the inside IP ?

If you are using a NAT statement for the VPN traffic please add route-lookup keyword to it and then check.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Thanks Aditya - I believed with the NAT statement we had in place we did not need the Route-lookup keyword at the end.  However after adding the route lookup I can now access the inside interface so we must have been wrong.

Thanks for your help, much appreciated :)

Shaun

Hi Shaun,

Glad to assist. :)

Regards,

Aditya

Hi,

 

Im also facing same issue. unable to access inside interface IP over S2S VPN. after configuring route lookup in NAT , able to ssh inside IP (primary FW).  im unable to access secondary FW of HA pair. Please help.

Thanks for your quick response.

Review Cisco Networking products for a $25 gift card