We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you two Citrix podcasts. Learn about 2020 trends and get answers to your biggest Citrix questions!Listen Now

x

Cisco ASA VPN Access Subnet Access Issue

Bob
Bob asked
on
Medium Priority
364 Views
Last Modified: 2012-06-27
I have a network of several Cisco ASA's and would like to access them all using one vpn tunnel.  

I currently have the network setup where I can access most of the Hub ASA subnet, which is 192.168.20.0 255.255.255.0  and all the spoke ASA subnets such as 192.168.25.0 255.255.255.0 and 192.168.30.0 255.255.255.0

However the line we are using to assign the VPNAccess ip is...
ip local pool VPNAccess 192.168.20.230-192.168.20.235 mask 255.255.255.248
    which blocks out some of the ip's on the Hub network 20.

I changed the VPN Access to 172.16.20.0-172.16.20.100 mask 255.255.255.0 but then can't access the machines on the spokes.

I prefer to use the 172.16.20.0 subnet for my VPNAccess but don't know how to setup the Hub and Spoke ASA's to accomplish this.

Thanks for the help
Comment
Watch Question

CERTIFIED EXPERT
Commented:
You will have to modify the hub and spoke VPNs to support your new subnet.

There should be a line on the crypto map that references the access-list.  You have to modify the access list on both ends of the VPN.

HUB:

access-list VPN-Access extended permit ip 172.16.20.0 255.255.255.0 w.x.y.z 255.255.255.0


Spoke:

access-list VPN-Access extended permit ip w.x.y.z 255.255.255.0 172.16.20.0 255.255.255.0


Where w.x.y.z is the spoke subnet.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
Bob

Author

Commented:
Ok   Finely able to do this but still no joy.

Do I need to make a route entry somewhere to let the spoke know that it needs to use the hub to access the 172 subnet?
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.