Avatar of Matthew Galiano
Matthew Galiano
Flag for United States of America asked on

Access DMZ Vlan on Cisco ASA 5510 from seperate Cisco ASA 5505

Afternoon All,

I have two cisco ASA's, in seperate locations on different WANs. One is a 5510 and the other is a 5505. Both have security plus licenses. There is a vpn setup between the two devices so that I can access the inside networks from either location without issue. There is a DMZ setup on the 5510 which I can access from the inside network of the 5510. However, I am unable to access the DMZ interface from the 5505. I have a web server sitting on the 5510 DMZ interface and I need to be able to access it from the inside interface on the 5505.

What needs to be done to accomplish this?
Cisco

Avatar of undefined
Last Comment
Matthew Galiano

8/22/2022 - Mon
lruiz52

Please post a sanitized config for both ASA's
Matthew Galiano

ASKER
Here is the 5505, please ignore dmz1, its not the dmz in question. Its just being used for a seperate wireless network. The dmz I am trying to reach is on the 5510 config.

5510 coming.
5505.txt
Matthew Galiano

ASKER
5510
5510.txt
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
lruiz52

You need to specify the traffic in your crypto ACL's try adding the below;

On your ASA5510
access-list VPN extended permit ip 10.10.10.0 255.255.255.0 10.30.1.0 255.255.255.0

access-list vpn-nonat extended permit ip 10.10.10.0 255.255.255.0 10.30.1.0 255.255.255.0
access-list vpn-nonat extended permit ip 10.30.1.0 255.255.255.0 10.10.10.0 255.255.255.0


On your ASA5505
access-list outside_1_cryptomap extended permit ip 10.30.1.0 255.255.255.0 10.10.10.1 255.255.255.0


access-list nonat extended permit ip 10.10.10.0 255.255.255.0 10.30.1.0 255.255.255.0
access-list nonat extended permit ip 10.30.1.0 255.255.255.0 10.10.10.0 255.255.255.0

Hope it helps.
Matthew Galiano

ASKER
Thanks for the response but I still cannot ping my webserver on the dmz 10.10.10.10
Matthew Galiano

ASKER
Any other ideas?
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
lruiz52

login to your ASA 5510 and type the below command, then post output


packet-tracer input inside icmp 10.30.1.20 8 0 10.10.10.10 detailed
ASKER CERTIFIED SOLUTION
Matthew Galiano

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Matthew Galiano

ASKER
Was missing an access group.