cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
1176
Views
2
Helpful
9
Replies

Need to reach internal network without Anyconnect VPN

Alok.Prabhakar
Level 1
Level 1

Hi All,

Wanted to know if any software/hardware to reach the internal network (DC devices) when the Anyconnect VPN is down/not reachable.
(By passing the VPN so that we can connect for troubleshooting purposes.)

9 Replies 9

as VPN or as mgmt ?

Mainly for mgmt puposes. So that we can get access to the devices with connecting VPN

so SSH is not optional here ?

SSH would be helpful. But without VPN connected we would not be able to SSH into the devices, wanted to change that when VPN is down so that we can login to them.

you can, what you need only is NATing in ASA
SW private IP -> NATing ASA port 22 -> public IP 
when you not connect via VPN you can use public IP of ASA using port 22 access to SW private IP.

Sorry forgot to mention, we have FTDs managed by FMC.
We would also like to get access to other devices like routers and switches in DC not just Firewall.

router1 private IP port 22 -NATing -> public IP port 1022 
router2 private IP port 22 -NATing-> public IP port 2022
..etc. 
each one have it port to access.

Thank you. But my public IP keeps changing right and also we need to make changes on FMC(not in FTD CLI) is what TAC informed.

public IP keep changing Need then VPN. 
anyconnect NO 
then last as I know is using flexVPN remote access 

Review Cisco Networking for a $25 gift card