Solved

site-to-site vpn management

Posted on 2013-12-03
1
319 Views
Last Modified: 2013-12-03
I currently have a site-to-site vpn configured with our main office and a remote office.  Behind the main office is a syslog/snmp server.  the remote office asa only has two interface, "outside" and "inside" inteface.  

The main office (internal subnet) can ssh to the remote office's "outside" interface.  With this connectivity, i can use cat tools to back up the config,  

Here's where my issue lies.  I CANNOT ssh nor ping the "inside" interface of the remote office's ASA from the main office's internal subnet.
I would like to send syslog/snmp-traps from the remote ASA to the syslog/snmp server located behind the main office using the inside interface of this remote ASA.  There are no ACL denies, NAT issues that is obvious from the ASA monitor.  Note that it's the same thing that's happening from remote office's to the main office's inside interface; i cannot ping it nor ssh to it.  

Anyone seen this kind of issue with a site-to-site VPN established using two ASA's?
I will attach some configs for better understanding.

Thanks
0
Comment
Question by:FREDARCE
1 Comment
 
LVL 2

Accepted Solution

by:
showard2007 earned 250 total points
ID: 39694019
Try the command "management-access inside". Then make sure your ssh statements allow for the main office's internal subnet to the inside interface of the device.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

 One of the main issues with network wires is that you never have enough.  You run plenty and plan for the worst case but you still end up needing more.  What many people do not realize is with 10BaseT and 100BaseT (but not 1000BaseT) networks you …
When posting a question about a Cisco ASA, Cisco Router or Cisco Switch, it can aid diagnosis if a suitably sanitised copy of the config is provided. It is much better to leave as much of the configuration as original as possible, as it could be tha…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question