Solved

Cisco ASA 5505 VPN accessing Inside and DMZ VLAN

Posted on 2013-11-17
4
886 Views
Last Modified: 2013-11-23
We have a terminal that people are accessing via a VPN into the Cisco ASA. The ip address of the ts is 192.168.16.2 (ASA 192.168.16.254). Works fine (users get allocated 192.168.200.x IP address via VPN). However, a site that the users go to is on the same subnet. Thought of getting around it by using a second NIC in the TS, configuring it as 192.168.100.1, setting up DMZ VLan in ASA. Also through TS Host, have configured it for lower colour depth, etc etc. They then can vpn in and access the tserver on 192.168.100.1. I have set it up but cannot access the termianl server on this address. The TS can ping the gateway okay (192.168.100.254). I have included a copy of the config and a diagram of how it is to ber setup.

Thanks,Diagram of setupVPN-Mulitple-Vlans-Conf.txt
0
Comment
Question by:greentriangle
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 16

Expert Comment

by:btassure
ID: 39655723
If I understand this correctly you have a number of remote users who all need to access a terminal server which has (had?) a single IP on the 192.168.16.0 network. This is the same subnet as the remote site.

I assume that because it was working you were tunnelling all traffic over the VPN which in turn prevented the remote users from being able to see the 192.168.16.0 network at their site?

If all of the above is correct, would it not be possible for you to only tunnel the IP of the terminal server? Assuming it is not in use and required at the remote site?

Failing all of that have you checked the TS config to ensure it is actually listening on the new NIC's IP address? Depending on how it was built it might not be set to listen for connections on all IPs...
0
 

Author Comment

by:greentriangle
ID: 39655814
Hi. The terminal server is configured as 192.168.16.2. Unfortuanately, there is also a server at the remote site with the same IP address, hence the reason setting up a different address for the TS (192.168.100.1). The NIC is listening okay on 192.168.100.1 and has been configured under TS Host configuration for the external RDP on that IP Address.
0
 

Accepted Solution

by:
greentriangle earned 0 total points
ID: 39656115
Hi there. Problem has been resolved so all good. Cheers!
0
 

Author Closing Comment

by:greentriangle
ID: 39671036
Fixed internally
0

Featured Post

Prevent Ransomware with Total Security Suite

With recent ransomware attacks topping the headlines, it might seem like there'e no hope in the battle against these advanced threats. Learn more about how WatchGuard's Total Security Suite can effectively prevent ransomware attacks including Petya 2.0 and WannaCry!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question