cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1203
Views
0
Helpful
6
Replies

site2site - HowTo telnet\ssh other side

ofir
Level 1
Level 1

I have a working site2site between 2 ASA5520 8.2(3)

I want side A to be able telnet\ssh to side B's ASA

using the telnet command would do it or should I also add an access-list?

6 Replies 6

Gustavo Medina
Cisco Employee
Cisco Employee

Hi,

ASA-A---------------L2L----------------------ASA-B

   |                                                     |

X.X.X.X                                           Y.Y.Y.Y

side B:

telnet X.X.X.X Z.Z.Z.Z inside   >>> Z.Z.Z.Z is the subnet mask.

manegement-access inside

Regards,

this should be on side B? I would assume on A as you have to open access to A from B

Yes that was for side B. That's all you need as you said the tunnel was already working between both ASAs therefore the communication should be good at this point. From hosts behind A, are you able to ping the inside interface of ASA-B?

Regards,

to make sure we're on the same page

all hosts behind A can access ASA_A - both ping and telnet

all hosts behind B can access ASA_A by ping but NOT telnet

I need hosts behind B to access ASA_A using telnet

On the first post it says:  "I want side A to be able telnet\ssh to side B's ASA"

On your last post it says: "I need hosts behind B to access ASA_A using telnet"

It doesn't matter, after all is the same thing for both; you said "all hosts behind B can access ASA_A by ping but NOT telnet" that means that the management-access command is aready in place for ASA_A. Could you post the "sh run telnet" from ASA_A? it has to include the hosts behind ASA_B

telnet X.X.X.0 255.255.255.0 mgmt
telnet Y.Y.Y.0 255.255.255.0 mgmt

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: