01-10-2022 12:21 PM - edited 01-10-2022 12:28 PM
If I had management admins sitting at Site 10 on service VPN 10, what is the best practice to get them to be able to access vManage in order to administer it? vManage sits at a separate site. This is on-prem if that matters.
Solved! Go to Solution.
01-11-2022 01:07 PM
01-10-2022 01:10 PM
Hi
Best practice is always have a management network not only for vManage but all device you have.
01-10-2022 01:20 PM
Yes, which is what I'm trying to do, but the technical HOW to do it is the problem.
01-10-2022 05:57 PM
Well, it will depends on how your environment works. This is difficult to give you a direction whithout knowing you network. I´ll tell you how my environment works. We have an unique network for management and our devices has one interface (loopback or int vlan) on this nework. Then we have firewall filtering who (network) can get access to this mgmt network and of course, TACACS.
We have VRF everywhere, so, one VRF is dadicated to carrie management traffic from site to Data Center. VRF is really nice as it segregates traffic from the begining to the end.
On the mgmt network you can allow only HTTPS, TACACS, Syslog, SSH and others mgmt protocols and dont give access to the internet from this mgmt network.
We also use some kind of VDI to get access using HTTPS or SSH. This way, the connection doesn´t start from admin machine but from a controlled environment. The admin machine serves only as a terminal to access this VDI environment.
This can go on and on depending on how complex is your environment and how secure you want to be.
01-10-2022 05:55 PM
01-10-2022 06:47 PM
That makes sense. So the users would use that vEdge as a hop into the management 512 subnet. Being able to route leak between 512 and 10 on that vEdge will be what I will look at next, though I may be back here. Thanks for this.
01-11-2022 11:33 AM
01-11-2022 12:53 PM
I think I understand. So by putting the cloud vEdge's VPN10 in the same subnet as the controller's VPN512, it will be able to communicate with everyone on that subnet despite being in a different VPN (once the VPN10 users cross the tunnels and get to that vEdge). Nice! I just tested that and I was able to ping vManage's VPN512 address from VPN10 on the vEdge.
Am I understanding this correctly?
01-11-2022 01:07 PM
01-11-2022 01:23 PM
Awesome. Just configured it and it worked. Thanks a ton for your help!
01-14-2022 11:20 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide