How to allow access to VLAN from outside (ASA and 881)

I have two Cisco routers ASA5510 and 881.
881 has two vlans, VLAN1 and VLAN2. VLAN1 is on 10.10.25.0 sub-net and computers from VLAN1 can communicate and authenticate to 10.10.0.88 which is a domain server.
How can I configure 881 so it will allow communication the other way around? If I try to ping VLAN1 or access the  computer (10.10.25.10) from 10.10.0.88 i am unable to do it.

Please check the attached txt with 881 config and the image with network layout.

Thank you for your help.
881-config.txt
network-layout.png
kesermAsked:
Who is Participating?
 
ddiazpCommented:
Easy right off the bat:

Your 10.10.0.88 host probably does not have a route to 192.168.1.0/24, make sure you have that route on your ASA:


ip route 192.168.1.0 255.255.255 10.10.0.2
0
 
Don S.Commented:
The ASA is not a router.  It is a firewall and as such, it likely would have rules not allowing ping to go through in that direction.  check the rules in the asa to see what is explicitly allowed through.
0
 
kesermAuthor Commented:
Thanks for the reply!

ddiazp

Did you mean:
ip route 10.10.25.0 255.255.255 10.10.0.2

I'll have to wait until morning to make the change.
0
How do you know if your security is working?

Protecting your business doesn’t have to mean sifting through endless alerts and notifications. With WatchGuard Total Security Suite, you can feel confident that your business is secure, meaning you can get back to the things that have been sitting on your to-do list.

 
ddiazpCommented:
255.255.255.0....
 and yeah i jimped a bit too ahead of myself, make sure icmp echo and echo reply are allowed on the firewall
0
 
kesermAuthor Commented:
ASA does not allow 'ip route' command, I get:
'Invalid input detected at '^' marker.'

This is in production so I can't play much wit it. Should I use:

route inside 10.10.25.0 255.255.0 10.10.0.2
0
 
kesermAuthor Commented:

ASA:
'route inside 10.10.25.0 255.255.0 10.10.0.2' worked.


0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.