Cisco ASA Configuration Help Required - Security Levels

Basically need a host in a lower level vlan to be able to access a host at the end of a VPN link that is running from another vlan which is at a higher level. Just need to know what config I need to do this. i have attached a diagram to show what I would like to achieve

Current setup of network
greentriangleAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

InteraXCommented:
For this, I've assuming you have the VPN in place. Do you implicitly trust the VPN traffic?

On the firewall closest to the host initiating the traffic, you will need to create an ACE on the interface the traffic arrives on to allow the traffic through.

If you implicitly trust VPN traffic at both ends, that's it. If you don't implicitly trust VPN traffic, you will need to create a matching ACE on the remote firewalls VPN interface.
0
fgasimzadeCommented:
access-list extended permit tcp  host 192.168.200.2 eq 3277 tcp host 192.168.200.2 eq 3277

Apply this access list to ASA interface with security level 50 (192.168.200.0)

Do you have any NAT configured on ASA between these interfaces? If yes, you would need an exempt

You would also need to add 192.168.200.0 subnet to the encrypted subnets on VPN device
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
greentriangleAuthor Commented:
Still looking into...
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.