?
Solved

How to troubleshoot network issue with Cisco ASA, Router, Wireless AP, and Switch

Posted on 2013-12-09
6
Medium Priority
?
677 Views
Last Modified: 2013-12-21
Hello experts - I recently assumed additional responsibilities at work which include all switching and routing.  I'm not an expert (yet) so could use some help in getting started troubleshooting a particular issue.  I am attempting to setup a private wireless network that will connect Apple devices to my LAN for access to email and RDP.  Its 90% there, the only remaining issue is that users on the wireless network can't access https sites which run on it.  Going out to the internet works fine with https, its just internally where the sites won't load.  The configuration is setup where the wireless access points are connected to a 2504 controller.  This is attached to a 4510 switch as is the 2811 router (gateway) and 5510 ASA (firewall).  In this case I believe the problem is on the router or switch since requests for internal sites shouldn't be routed to the ASA.  

That is where I'm stuck.  I am not certain how best to troubleshoot access issues like this between devices.  I would appreciate any tips or advice to get me going, thanks!
0
Comment
Question by:First Last
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 12

Expert Comment

by:Henk van Achterberg
ID: 39706721
the problem is that you try to visit the external IP addresses that reside on the outside interface of the ASA.

You can do two things:

1. configure the DNS server to return the inside IP adresses of the server instead of the external IP's
2. NAT the external IP addresses FROM the inside TO the inside (and change the source IP address to the interface).
0
 
LVL 1

Author Comment

by:First Last
ID: 39706732
Hi henkva - perhaps I am misunderstanding your reply but I don't think it applies in this case.  I am already on the inside LAN connected to the wireless network.  I can ping, RDP, an access internal sites using HTTP but not HTTPS.  Everything out to the internet works fine as well.  So in my case these sites don't exist outside the LAN, they are only accessible internally.
0
 
LVL 12

Expert Comment

by:atrevido
ID: 39708889
can you post a network drawing so we can see how things are connected, it can be hand drawn and scanned if you don't have time to do a traditional Visio.  

Also, post a show run from your router, scrub the public ip addresses though
0
Supports up to 4K resolution!

The VS192 2-Port 4K DisplayPort Splitter is perfect for anyone who needs to send one source of DisplayPort high definition video to two or four DisplayPort displays. The VS192 can split and also expand DisplayPort audio/video signal on two or four DisplayPort monitors.

 
LVL 1

Author Comment

by:First Last
ID: 39708928
Ok, that will take a little time, I'll work on it today.
0
 
LVL 1

Accepted Solution

by:
First Last earned 0 total points
ID: 39721487
I wound up working with Cisco on this and determined its not a Cisco issue but a problem with VMware networking.
0
 
LVL 1

Author Closing Comment

by:First Last
ID: 39733388
Found own answer
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question