Solved

Cisco ASA 5505 VPN accessing Inside and DMZ VLAN

Posted on 2013-11-17
4
877 Views
Last Modified: 2013-11-23
We have a terminal that people are accessing via a VPN into the Cisco ASA. The ip address of the ts is 192.168.16.2 (ASA 192.168.16.254). Works fine (users get allocated 192.168.200.x IP address via VPN). However, a site that the users go to is on the same subnet. Thought of getting around it by using a second NIC in the TS, configuring it as 192.168.100.1, setting up DMZ VLan in ASA. Also through TS Host, have configured it for lower colour depth, etc etc. They then can vpn in and access the tserver on 192.168.100.1. I have set it up but cannot access the termianl server on this address. The TS can ping the gateway okay (192.168.100.254). I have included a copy of the config and a diagram of how it is to ber setup.

Thanks,Diagram of setupVPN-Mulitple-Vlans-Conf.txt
0
Comment
Question by:greentriangle
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 16

Expert Comment

by:btassure
ID: 39655723
If I understand this correctly you have a number of remote users who all need to access a terminal server which has (had?) a single IP on the 192.168.16.0 network. This is the same subnet as the remote site.

I assume that because it was working you were tunnelling all traffic over the VPN which in turn prevented the remote users from being able to see the 192.168.16.0 network at their site?

If all of the above is correct, would it not be possible for you to only tunnel the IP of the terminal server? Assuming it is not in use and required at the remote site?

Failing all of that have you checked the TS config to ensure it is actually listening on the new NIC's IP address? Depending on how it was built it might not be set to listen for connections on all IPs...
0
 

Author Comment

by:greentriangle
ID: 39655814
Hi. The terminal server is configured as 192.168.16.2. Unfortuanately, there is also a server at the remote site with the same IP address, hence the reason setting up a different address for the TS (192.168.100.1). The NIC is listening okay on 192.168.100.1 and has been configured under TS Host configuration for the external RDP on that IP Address.
0
 

Accepted Solution

by:
greentriangle earned 0 total points
ID: 39656115
Hi there. Problem has been resolved so all good. Cheers!
0
 

Author Closing Comment

by:greentriangle
ID: 39671036
Fixed internally
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question