cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
740
Views
5
Helpful
4
Replies

VPN from DMZ interface to Outside interface

craig-mitchell
Level 1
Level 1

Have an ASA 5510. Setting up a new DMZ zone for wireless and it will only have Internet access. Can someone explain the steps to me so that users on this new DMZ subnet can VPN into the Outside interface on the same ASA? Thank you!

Sent from Cisco Technical Support iPhone App

1 Accepted Solution

Accepted Solutions

You can't VPN to the outside interface. The ASA doesn't allow that if you are on the inside or DMZ, you have to be somewhere on the outside to allow VPN to the outside. You could enable the configuration to allow VPN session to the DMZ interface instead.

I hope this helps.

View solution in original post

4 Replies 4

You can't VPN to the outside interface. The ASA doesn't allow that if you are on the inside or DMZ, you have to be somewhere on the outside to allow VPN to the outside. You could enable the configuration to allow VPN session to the DMZ interface instead.

I hope this helps.

craig-mitchell
Level 1
Level 1

Okay, so I could just apply the same crypto map that is on my outside interface to this new DMZ interface and then just issue a new pcf file for the clients to use when they are on the DMZ wireless network?

Sent from Cisco Technical Support iPhone App

That is correct

Sent from Cisco Technical Support iPhone App

craig-mitchell
Level 1
Level 1

One other related question. How could I allow traffic from this new wireless DMZ to access resources that are already being served to the Internet such as a web server. Is there a way to allow this hairpin traffic to exit the ASA and come back in? Thanks.

Sent from Cisco Technical Support iPhone App

Review Cisco Networking for a $25 gift card