cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1093
Views
0
Helpful
10
Replies

I can't getting log and snmp through vpn

Yasm
Level 1
Level 1

Hello,

I can't getting log and snmp through vpn when i want to reach management interface, either remote acces to asdm and ssh is ok.it's strange thank you for your help.

Best regards,

2 Accepted Solutions

Accepted Solutions

If you want to access the ASA over a VPN connection, you would not use (or need to use) NAT.  You only need to add the command management-access .

So lets say you want to use the IP associated with the interface named inside to manage the ASA.  You would then enter the command management-access inside

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

Do you require any more assistance with this issue?  If not please select a correct answer and rate any helpful posts.

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

10 Replies 10

Yasm
Level 1
Level 1

With management interface.

do you the command management-access (where managment interface is the interface name) configured on your ASA?

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

Hello,

Yes

#  show run management-access
management-access DMZ-Administration

Best regards,

Have you verified that the crypto ACLs are correctly configured?  Have you defined that the SNMP server is reachable through the outside interface on the remote ASA?

Please post the full sanitised running configuraiton of devices at both ends of the tunnel.

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

Hello thank for our reply,

Regarding the crypto ACLs, we reach other site through vpn without problem snmp or log.I will check that we can reach the snmp server through outside interface.

Sorry and i try to recover the running config,

the vpn is defined on outside interface we want to put nat on outside interface in order to reach management interface is it possible ?

Best regards,

the vpn is defined on outside interface we want to put nat on outside  interface in order to reach management interface is it possible ?

Not sure I understand what you want to do here.  Is your outside interface connected to the internet? 

From where do you want to access the ASA management interface (over the VPN, from internet..etc)?  if you want to nat to the inside interface IP, this is not supported.  Management of the ASA on a different interface than the one you entered the ASA on is not supported.

http://www.cisco.com/en/US/docs/security/asa/asa90/configuration/guide/access_management.html#wp1329954

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

Hello Marius,

Yes we use outside interface connected to internet, we  want to reach management interface through outside interface connected  to internet over vpn with nat.

But if is not supported we have no choise, what we can do ? thank you for our link Cisco

Best regards,

If you want to access the ASA over a VPN connection, you would not use (or need to use) NAT.  You only need to add the command management-access .

So lets say you want to use the IP associated with the interface named inside to manage the ASA.  You would then enter the command management-access inside

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

Thank's Marius,

good afternoon.

Best regards,

Do you require any more assistance with this issue?  If not please select a correct answer and rate any helpful posts.

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts