We help IT Professionals succeed at work.

ASA can access to router through VPN

eemoon
eemoon asked
on
Medium Priority
45 Views
Last Modified: 2020-02-10
Hi Please see the topology ASA1------internet -------ASA2 --------router1--------router2 or server. The two ASA are connected by point to point VPN. My question is if or how ASA1 or users behind the ASA1 can access router2 or server? Thank you
Comment
Watch Question

David Johnson, CDSimple Geek from the '70s
CERTIFIED EXPERT
Distinguished Expert 2019

Commented:
each router will have to have port forwarding rules in place to go from outside to inside.

Author

Commented:
Thank you for your fast reply. Yes it needs port forward, but I only know port forwarding can be used to the nearest network, such as, to any device in the network between ASA2 and router1, not the network between router1 and router2. If port forwarding can reach any device in network between router1 and router2, can you explain by sending a link? 
Simple Geek from the '70s
CERTIFIED EXPERT
Distinguished Expert 2019
Commented:
you are quite correct that it can only go up one level. so you would have to port forward on the ASA and thr router i.e.
AsA forward from WAN to 10,0.1.1 tcp port 80 to port 8080
router1 wan address 10.0.1.1
forward from wan to 192.168.0.20 port 8080 to 192.168.0.200 port 8080 to port 80