cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
738
Views
0
Helpful
2
Replies

L2TP VPN port forwarding to DMZ on ASA5525x (9.2)

farrukh19911
Level 1
Level 1

Hello everyone.

I have ASA5525x with 9.2 IOS. Can I forward the L2TP ports to DMZ, where I have configured L2TP Server?

2 Replies 2

Philip D'Ath
VIP Alumni
VIP Alumni

Is your ASA currently terminating any IPSec traffic?

Is your DMZ using public IP addressing, or do you have a spare public IP address you can assign/NAT to this host?

From local network it is working well. Also PPTP is working from outside without any problem.

I configured with the following settings, but it is not working. May be I missed any parameters?

object network L2TP-SERVER

  host 1.1.1.1

  nat (dmz,outside) static 46.46.46.35 service udp 1701 1701

object network L2TP-SERVER-500

  host 1.1.1.1

  nat (dmz,outside) static 46.46.46.35 service udp 500 500

object-group network WAN-IP

  network-object host 49.49.49.35

  network-object host 49.49.49.36

access-list OUTSIDE_IN extended permit udp object-group WAN-IP object L2TP-SERVER
access-list OUTSIDE_IN extended permit esp object-group WAN-IP object L2TP-SERVER

policy-map global_policy
class inspection_default

 inspect ipsec-pass-thru

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: