Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 616
  • Last Modified:

Routing to a DMZ in a spoke from a different spoke in hub and spoke VPN config

As a company, we use a hub and spoke configuration.

The hub is a Cisco ASA 5510. Spokes are Sonicwall TZ100.

I'm sitting behind one of the spokes @ 10.40.45.1/24. On another spoke @ 10.40.46.1, I've put a server in a DMZ. The gateway address of the DMZ in 10.40.200.1.

I'm not sure if this is a routing issue for the Cisco, or a routing issue for the sonicwalls, but I would like to reach the DMZ'd device @ 10.40.200.100 from my computer @ 10.40.45.100. The Cisco is @ 192.168.199.1

Thanks in advance.
0
kblackwel
Asked:
kblackwel
1 Solution
 
Pete LongConsultantCommented:
With a sonic wall on your site   - I'm not sure if it would work? but if you had an ASA it would,

You would need to add the distant DMZ Subnet mask to the cryptomap ACL that goes to the main site. Then you would need to go to the main site and add the DMZ subnet to  the other the cryptomap that handles the VPN to your site AND you would need to exempt that traffic from NAT (the command differ depending on the OS you are using)

Pete
0

Featured Post

Configuration Guide and Best Practices

Read the guide to learn how to orchestrate Data ONTAP, create application-consistent backups and enable fast recovery from NetApp storage snapshots. Version 9.5 also contains performance and scalability enhancements to meet the needs of the largest enterprise environments.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now