01-30-2014 08:15 AM
Hello,
I can't getting log and snmp through vpn when i want to reach management interface, either remote acces to asdm and ssh is ok.it's strange thank you for your help.
Best regards,
Solved! Go to Solution.
02-04-2014 11:59 PM
If you want to access the ASA over a VPN connection, you would not use (or need to use) NAT. You only need to add the command management-access
So lets say you want to use the IP associated with the interface named inside to manage the ASA. You would then enter the command management-access inside
--
Please remember to rate and select a correct answer
02-12-2014 07:35 AM
Do you require any more assistance with this issue? If not please select a correct answer and rate any helpful posts.
--
Please remember to rate and select a correct answer
02-03-2014 01:04 AM
With management interface.
02-03-2014 01:55 AM
do you the command management-access
--
Please remember to rate and select a correct answer
02-03-2014 06:06 AM
Hello,
Yes
Best regards,
02-03-2014 06:12 AM
Have you verified that the crypto ACLs are correctly configured? Have you defined that the SNMP server is reachable through the outside interface on the remote ASA?
Please post the full sanitised running configuraiton of devices at both ends of the tunnel.
--
Please remember to rate and select a correct answer
02-03-2014 07:52 AM
Hello thank for our reply,
Regarding the crypto ACLs, we reach other site through vpn without problem snmp or log.I will check that we can reach the snmp server through outside interface.
Sorry and i try to recover the running config,
the vpn is defined on outside interface we want to put nat on outside interface in order to reach management interface is it possible ?
Best regards,
02-04-2014 01:38 AM
the vpn is defined on outside interface we want to put nat on outside interface in order to reach management interface is it possible ?
Not sure I understand what you want to do here. Is your outside interface connected to the internet?
From where do you want to access the ASA management interface (over the VPN, from internet..etc)? if you want to nat to the inside interface IP, this is not supported. Management of the ASA on a different interface than the one you entered the ASA on is not supported.
--
Please remember to rate and select a correct answer
02-04-2014 07:57 AM
Hello Marius,
Yes we use outside interface connected to internet, we want to reach management interface through outside interface connected to internet over vpn with nat.
But if is not supported we have no choise, what we can do ? thank you for our link Cisco
Best regards,
02-04-2014 11:59 PM
If you want to access the ASA over a VPN connection, you would not use (or need to use) NAT. You only need to add the command management-access
So lets say you want to use the IP associated with the interface named inside to manage the ASA. You would then enter the command management-access inside
--
Please remember to rate and select a correct answer
02-12-2014 06:10 AM
Thank's Marius,
good afternoon.
Best regards,
02-12-2014 07:35 AM
Do you require any more assistance with this issue? If not please select a correct answer and rate any helpful posts.
--
Please remember to rate and select a correct answer
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide