cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4964
Views
0
Helpful
2
Replies

Need help setting up vpn on asa 5506X

Mike Baker
Level 1
Level 1

Good afternoon.  I am trying to setup an anyconnect vpn on a new asa 5506 and am struggling with getting some things to work.  I can reach a device configured on the inside network, but have not been able to get to asdm or ssh if I want to administer the asa remotely from the dsl line it will be on.  I know this is probabably trivial for an experienced person, but I am struggling.  Please comment and direct me to the correct blog or forum so I don't waste everyones time.  Thanks.

2 Replies 2

kj4cyv001
Level 1
Level 1

Since you got anyconnect going, your 99% there! In ASDM, click on Configuration, Device Management, Management Access, and then Management Interface. Choose Inside. Since you are VPN'ing in, you should be able to go to the management interface (The inside IP) of the firewall. Managing ASDM while VPN is secure. Just don't make any changes to the VPN configuration while you are VPN'ed. There is a way around that...

You can also click on Configuration, Device Management, Management Access, and then ADSM/HTTPS/SSH - put in the inside networks that you wish to be able to manage the firewall. I would NOT recommend allowing any outside networks (like 0.0.0.0) - but you can manage from outside IP's directly if you are careful and try to keep outside HTTPS/SSH access narrowed down to just a few outside fixed IP's that are 'owned' by you or your business. Managing a firewall directly from it's outside IP address is a must if you are changing IPsec passwords, certificates, or changing the VPN configuration. Don't use telnet on an outside interface if you don't have to for security reasons.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: