06-29-2007 07:19 AM - edited 02-21-2020 03:07 PM
I have an ASA 5510 that have remote access VPN service enabled. Users are able to logon and access inside resources no problem. the issue is the DMZ servers, like the web server, they can not access. Is there and easy way to allow this access for VPN users?
Thanks
Solved! Go to Solution.
06-29-2007 07:31 AM
That will allow you to hit your dmz servers. For instance if the dmz is 192.168.1.0, you can hit the servers by their dmz addresses 192.168.1.x etc.
Your other option is to use split tunneling which would allow you to access the servers via their public ip addresses which are translated in the ASA.
06-29-2007 07:24 AM
You need to add nat exemption for the dmz as you did for the inside.
access-list dmz_nonat extended permit ip any
nat (dmz) 0 access-list dmz_nonat
Please rate helpful posts.
06-29-2007 07:31 AM
That will allow you to hit your dmz servers. For instance if the dmz is 192.168.1.0, you can hit the servers by their dmz addresses 192.168.1.x etc.
Your other option is to use split tunneling which would allow you to access the servers via their public ip addresses which are translated in the ASA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide