cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
880
Views
0
Helpful
8
Replies

ASA 5512-X - created new vLAN, everything works on it except connecting to ASDM/Telnet

credibleitops
Level 1
Level 1

Got it all configured and inter-vlan traffic is flowing, I can get out to the internet, but I can't connect to ASDM from that vLAN. I added the Management Access entries for that network and interface, but it still doesn't work. From my research I think that's all I should need to do, so I'm not sure how to proceed.

Jeremy

1 Accepted Solution

Accepted Solutions

Thank you for the additional information. I do not see anything there that would prevent access using ASDM. So we must look a bit further. Can you post the output of

show run | include asdm

show flash | include asdm

show arp

You tell us that you can reach the Internet from this PC? So I assume that routing must be working ok. You tell us that the PC is learning its IP address from a DHCP server. Is that DHCP on the ASA? On the connected switch? A separate DHCP server?

When you attempt ASDM what IP address are you using?

Are there access lists configured, especially on the MD-Inside-Prod interface?

HTH

Rick

HTH

Rick

View solution in original post

8 Replies 8

kj4cyv001
Level 1
Level 1

Not sure how you are connecting to the vlan, but if you are on a vlanned switch, check to be sure the tagged/untagged/trunk ports and PVID directors are set properly. You should be able to ping the IP address of the subinterface of that vlan on the firewall. If you have a dhcp server on that vlan, set your pc on dhcp to confirm that you are indeed on the right vlan.

I'm sure that setting the Management Access entries for that network and interface is all you should have to do - make sure you are on the correct port and vlan ip address range.

You can also try putty and see if you can ssh in from that vlan, at least as a test anyways, if you have ssh enabled. 

I believe that we need some additional information to be able to give good suggestions about this issue. Can you answer these questions and provide this information:

- what is the IP address, mask, and gateway configured on the PC you are attempting access from?

- can the PC ping the address on the ASA?

- is ASDM configured and working correctly from addresses on other VLANs?

- would you post the output of show run | include telnet

- would you post the output of show run | include http

- would you post the output of show ip

HTH

Rick

HTH

Rick

- what is the IP address, mask, and gateway configured on the PC you are attempting access from?

IP - 172.28.4.3

Mask - 255.255.255.0

GW - 172.28.4.1

- can the PC ping the address on the ASA?

no

- is ASDM configured and working correctly from addresses on other VLANs?

This is the first vLAN we've created except for our Guest network, which is internet only

- would you post the output of show run | include telnet

**Removed outside interfaces from the output**

telnet 172.28.0.0 255.255.252.0 MD-Inside
telnet 192.168.1.0 255.255.255.0 Management
telnet 172.28.4.0 255.255.255.0 MD-Inside-Prod

- would you post the output of show run | include http

**Removed outside interfaces from the output**

aaa authentication http console LOCAL
http server enable
http 192.168.1.0 255.255.255.0 Management
http 172.28.4.0 255.255.255.0 MD-Inside-Prod
http 172.28.0.0 255.255.252.0 MD-Inside

- would you post the output of show ip

**Removed outside interfaces from the output**

System IP Addresses:
Interface Name IP address Subnet mask Method
GigabitEthernet0/1 MD-Inside 172.28.0.1 255.255.252.0 manual
GigabitEthernet0/1.70 MD-Inside-Prod 172.28.4.1 255.255.255.0 manual
GigabitEthernet0/1.168 Guest 192.168.168.1 255.255.255.0 CONFIG
Management0/0 Management unassigned unassigned DHCP
Current IP Addresses:
Interface Name IP address Subnet mask Method
GigabitEthernet0/1 MD-Inside 172.28.0.1 255.255.252.0 manual
GigabitEthernet0/1.70 MD-Inside-Prod 172.28.4.1 255.255.255.0 manual
GigabitEthernet0/1.168 Guest 192.168.168.1 255.255.255.0 CONFIG
Management0/0 Management unassigned unassigned DHCP

Thanks in advance, I really appreciate you guys' help.

Thank you for the additional information. I do not see anything there that would prevent access using ASDM. So we must look a bit further. Can you post the output of

show run | include asdm

show flash | include asdm

show arp

You tell us that you can reach the Internet from this PC? So I assume that routing must be working ok. You tell us that the PC is learning its IP address from a DHCP server. Is that DHCP on the ASA? On the connected switch? A separate DHCP server?

When you attempt ASDM what IP address are you using?

Are there access lists configured, especially on the MD-Inside-Prod interface?

HTH

Rick

HTH

Rick

Rick,

You sir are the man. When I read your question "When you attempt ASDM what IP address are you using?" I had a lightbulb moment. I was attempting to access ASDM via the old shortcut it created (which points to 172.28.0.1) from the newly created vLAN. I needed to access from 172.28.4.1 instead.

It was working properly, I was using the wrong IP address. 

Sorry to waste your time, but thanks!!

Jeremy

Jeremy

I am glad that we were able to solve this one. It was an interesting exercise and a good logical progression. First we looked for likely configuration issues and when we did not find configuration issues we looked for other types of mistakes that might cause this. Thank you for using the rating system to mark this question as answered. This will help other readers in the forum to identify discussions with helpful information.

HTH

Rick

HTH

Rick

We are on cisco managed switches, which I'm fairly certain are set up correctly. From the PC that's on the vLAN, I can ping the subinterface, but I cannot ping the management interface. My PC is using DHCP and has an appropriate IP address.

I am curious about your statement that you can ping the subinterface but cannot ping the management interface. Can you clarify what is the subinterface and what is the management interface? And what address are you using when you attempt ASDM?

Additional questions:

- how are you attempting to start ASDM?

- when you attempt to start ASDM what happens? Do you get a prompt? Do you get an error message? If so what message? Does it just time out?

HTH

Rick

HTH

Rick
Review Cisco Networking for a $25 gift card