Can't access management interface via vpn connection
Hi all,
I can't seem to be able to manage my ASA 5510 when I connect via vpn. My asa sits at a remote colo, and from my office i can connect fine. I have it configured as management-access (dmz), bc as of now we are just doing some staging and all the servers are in the dmz interface.
When i connect with the vpn client, in the routes it sees 192.168.1.0 255.255.255.0 which is the management network/interface.
For some reason I can't get access to 192.168.1.1 to use the ASDM.
Here is how i did my vpn via CLI
isakmp enable outside
isakmp identity address
isakmp policy 10
authentication pre-share
encryption des
hash md5
group 2
lifetime 86400
ip local pool vpnpool 10.1.1.2-10.1.1.10
access-list split_tunnel standard permit 192.168.200.0 255.255.255.0
access-list split_tunnel standard permit 192.168.100.0 255.255.255.0
access-list split_tunnel standard permit 192.168.1.0 255.255.255.0
group-policy xxxxx internal
group-policy xxxxx attributes
dns value
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split_tunnel
username xxxxx password
username xxxxxx attributes
vpn-group-policy xxxx
username xxxxxx password
username xxxxxx attributes
vpn-group-policy xxxx
username xxxx password
username xxxx attributes
vpn-group-policy xxxx
tunnel-group xxxx type ipsec-ra
tunnel-group xxxx general-attributes
address-pool vpnpool
tunnel-group xxxx ipsec-attributes
pre-shared-key
access-list vpnra permit ip 192.168.200.0 255.255.255.0 10.1.1.0 255.255.255.0
access-list vpnra permit ip 192.168.100.0 255.255.255.0 10.1.1.0 255.255.255.0
access-list vpnra permit ip 192.168.1.0 255.255.255.0 10.1.1.0 255.255.255.0
nat (inside) 0 access-list vpnra
nat (dmz) 0 access-list vpnra
nat (management) 0 access-list vprna
crypto ipsec transform-set md5des esp-des esp-md5-hmac
crypto dynamic-map dynomap 10 set transform-set md5des
crypto map vpnpeer 20 ipsec-isakmp dynamic dynomap
crypto map vpnpeer interface outside
Any help would be much appreciated
it seems like you are missing a line:
management-access "interface"
http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/m_711.html#wp1631964
Similar Messages
-
Window 8.1 system unable to access network shares via VPN connection
Is there something inherent to Windows 8.1 that prevents it from accessing shares on a domain?
I know that it cannot join a domain, but does that also mean that it cannot access shares which are on a domain?
My problem is that I have several user that are running windows 8.1 that are connecting to our network via a VPN.
The users have domain accounts but their computers as windows 8.1 cannot joined to the domain.
So to access network shares they have to use their domain credentials to create a VPN connection.
Once connected the user can RDP to systems on the domain using their domain accounts, so I know that their user names/passwords and permissions are correct. They can access these systems using the computer name, so I don't feel that I have a DNS issue.
They can see the shares on our file server, but when they try to access their departments shared file, they receive an access denied message. There are a few shares that are completely wide open, shared to all users and all departments but they cannot access
those shares either.
You can ping the file server, from the the client when they are connected to the VPN but you just cannot access any of the shares.
So...
I am thinking that it has something to do with windows 8.1 and not being able to join a domain, but I cannot find anything to explicitly support this thought.
Other users running a variety different OS (windows 7, OSX, Linux) can all access the shares without any problems via the VPN, so I am a little stumped.I have done some more testing and oddly enough I can map a drive if I use the IPaddress, but not the computer name, when checking the check box "connect using different credentials"and providing they users domain credentials.
This seems to point to a DNS issue, one would think, but I can hit the file share server by name \\fileserver.dev.lan
I can see all the shares, so dns seems to be fine right?
So I don't understand why I can map a drive using do the IPaddress and not the machine name, but yet I can see and ping the server by name?
When I try to create a mapped drive by machine name I receive the following message:
Windows cannot access \\fileserver.dev.lan\all
You do not have permissions to access \\fileserver.dev.lan. contact your network administrator to request access.
But if I use the \\x.x.x.x\all using the very same user and password I get connected with no problem.
This only seems to happen on windows 8.1, which leads me to think that has something to do with OS.
I am thinking about upgrading to windows 8.1 pro, but I don't want to go though the hassle and expanse is the OS is not the problem. -
If i connect an external hard drive to a time capsule, can i access this drive via internet?
If the drive can be accessed in local lan, then it can be accessed from internet assuming you have setup using one of the remote access methods.
See remote access here.
https://discussions.apple.com/community/wireless/airport?view=documents -
Can not access home network via ipod touch, password entered not accepted
Can not access home network via ipod touch, password entered not accepted
Trying to help my son set up his ipod touch to connect to the network and the password I entered is not accepted.
1. Which password is required? I entered the password I use for logging into my router
2. The home network is recognized, when selected it requires a password to be entered, but I am just not sure what password it is looking for to connect.
I have not been able to find any information on this subjectjersey0904, Welcome to the discussion area!
You need to enter the wireless encryption password... not the administrative password for the router. -
Can anyone suggest a free fast VPN connection
Can anyone suggest a free fast VPN connection.
i want to access streaming video (ie hulu.com)that is blocked in canada. Hotspot Shield works but is way too slow and I get stuttering and frozen video.
Any suggestions would be appreciated
Thanks in advance
DaveFast and free? I'm surprised you can even find slow and free. I use StrongVPN. It is fast, but it isn't free at $15/month.
-
Can't access mail - getting message the connection to the server has timed out
can't access mail - getting message the connection to the server has timed out
Hi mtc,
Has it worked before?
Are you running any anti virus apps?
If using a browser to login via WebMail, does that work? -
Since downloading the IOS7 I can't access the internet via a wifi. I would like to remove it, is it possible? I have the ipad2
Sorry, no. Apple does not support downgrading.
Have you tried to go into your settings, reset, reset network settings? It'll erase your current network from your iPad and let you start over. -
I can't access Itunes Store via my Itunes. When Itunes start, CPU always 100%, I've tried uninstall and reinstall Itunes but it seems to be useless. Please help !!!
I can't access Itunes Store via my Itunes.
Is iTunes endlessly saying "Accessing iTunes Store"? Or is something a bit different going on? -
I just bought a brand new iPhone 5s and a huge problem is that when i try to sync my music to my iPhone 5s, under the music tab it says that i can only access my music via iCloud. is there anyway to sync your music from your computer?????
The ! sign before the song means that the actual song is no longer on your computer and/or iTunes library.
-
Can Oracle Access Manager do protocol translation and act as a gateway for multiple SAML2 IdP's talking back to a WS-Fed (RP/SP) ?
<-> SAML2 (IdP) (multiple namespaces)
WS-Fed (RP) <-> SAML2 (IdP) (multiple namespaces)
<-> SAML2 (IdP)
Sincerely,
AdamCan Oracle Access Manager do protocol translation and act as a gateway for multiple SAML2 IdP's talking back to a WS-Fed (RP/SP) ?
<-> SAML2 (IdP) (multiple namespaces)
WS-Fed (RP) <-> SAML2 (IdP) (multiple namespaces)
<-> SAML2 (IdP)
Sincerely,
Adam -
I can't see my files on my USB shared drive. It shows there is lots of space taken up, but I can't access the files via my Mac. How do I see them? I also can't see them on my iPad using FileBrowser.
You don't have access to it to configure it via Time Machine? You lost me on that one, Time Machine is used for Backup.
Here is a basic article on the first setup and what you should see:
http://support.apple.com/kb/HT1178
To configure Time Capsule you should be using "Airport Utility" 5.3 or higher that is located in the Utilities folder. You can tell if its version 5.3 because the icon will have blue lines instead of orange lines like the older versions. Since you are running Leopard 10.5.6 and you ran Software Update you are probably already running the latest 5.3 version.
The light flashing amber means you haven't entered enough information so that it can get to the internet. Once you have that info entered the light will turn green.
If your absolutely sure your CAT5 cables are good you can try a hard reset. I think you have to push the reset button on the back and hold it for 5 seconds or so until the amber light blinks rapidly, then when you release the button it does the reset then.
http://support.apple.com/kb/HT1300?locale=en_US
Hope this helps! If not I would probably call AppleCare support or see if you can exchange it.
-Dan -
Firefox opens up, but, this morning, I can't access any links via Firefox. I can via Explorer.
A possible cause is security software (firewall) that blocks or restricts Firefox or the plugin-container process without informing you, possibly after detecting changes (update) to the Firefox program.
Remove all rules for Firefox from the permissions list in the firewall and let your firewall ask again for permission to get full unrestricted access to internet for Firefox and the plugin-container process and the updater process.
See:
*https://support.mozilla.com/kb/Server+not+found
*https://support.mozilla.com/kb/Firewalls -
How we can disable access to BOM via the Display Master Recipe (C203)?
Hi Gurus,
How we can disable access to BOM via the Display Master Recipe (C203)?
Thanks!Hi Mae Baraquio
Have you tried screen variant to make it as display mode.
please refer below document for your reference.
Learning SHD0 with Example
if you find any query kindly revert back.
Thanks & Regards
Sandeep Kumar Praharaj -
How can i access web when i am connected through a proxy?
HI,
I am rakesh from bangalore. I want to know how can i access web when i am connected to internet throug a proxy. are there any classes to handle this in java.net package?
Thanking you
Rakeshthe URL class can also handle a proxyserver.
URL urlobj = new URL("http", proxyhost, proxyport, url); -
Can not access ASAs inside interface via VPN tunnels
Hi there,
I have a funny problem.
I build up a hub and spoke VPN, with RAS Client VPN access for the central location.
All tunnels and the RAS VPN access are working fine.
I use the tunnels for Voip, terminal server access and a few other services.
The only problem I have is, that I could not access the inside IP address of any of my ASAs, neither via tunnels nor via RAS VPN access. No telnet access and no ping reach the inside interfaces.
No problem when I connect to the interface via a host inside the network.
All telnet statments in the config are ending with the INSIDE command.
On most of the ASAs the 8.2 IOS is running on one or two ASAs the 8.0(4).
For the RAS client access I use the Cisco 5.1 VPN client.
Did anybody have any suggestions?
Regards
MarcelMarcel,
Simply add on the asas you want to administer through the tunnels
management-access
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/m.html#wp2027985
for asa5505
management-access inside
for all others if you have management interface management0/0 defined then:
management-access management
then you may need to allow the source , for example if RA VPN pool network is 10.20.20.0/24 then you tell asa that network cann administer asa and point access to inside, but sounds you have this part already.
telnet 10.20.20.0 255.255.255.0 inside
http 10.20.20.0 255.255.255.0 inside
same principle for l2l vpns
Regards
Maybe you are looking for
-
Over the past few months I have been having issues every time that I log onto my Hotmail account. My Foxfire has seemed to be "buggy" for the past three upgrades but now mostly everything is working well. When I log onto one of my Hotmail accounts, I
-
Pur requisition manually or through MRP
Dear Friends Please sapre some time for my querries 1 How do I know that a particular Pur requisition was made manually or through MRP? 2 How to insert company logo in Printout of Purchase order? 3 How we can check that what are the documents
-
How Do You Annotate a Graphic Such as your Signature in PDF Using Preview?
Hi. I'm filling out a form that needs a signature. How do you annotate your signature (as a graphic perhaps?) to the PDF using Preview. Thanks in advance. Gbu.
-
Converting Word 2007 to PDF problem
I have Word 2007 and Adobe Acrobat 9. When I try to save my word file to PDF the PDF font looks distorted throuhout the document. I'm using standard fonts and I have done this many times before without a problem. This just started today.
-
Database does not exist, but visible in EAS console
Dear Sir/Madam, We had a problem with a corrupted security file. We have replaced the corrupted essbase.sec with an older version. Now it all works again, but when I open the tree in EAS console, I can see two databases which didn't exist before the