cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
345
Views
0
Helpful
4
Replies

VPN on Outside Interface of ASA 5520

IsaacKnoflicek
Level 1
Level 1

I'm able to connect to VPN using the Inside interface of my ASA 5520 however when I try to connect to the Outside Interface it acts like there's nothing there.

I ran NMAP on both interfaces and the Inside interface is listening on 10000/TCP but the External is not (or it's being blocked?).

I'm following the instructions in the ASA book, but they use the Outside interface and it just works. I don't think we're doing any special blocking on that port. What else am I missing?

Thanks,

Isaac

4 Replies 4

grant.maynard
Level 4
Level 4

so your VPN terminates on the inside of your ASA? That's a little unusual, it's normally the outside. In either case you'll only be able to connect to the interface which is "facing you".

It's just not working on the Outside, I'd prefer it that way. To test it I am comming from the Inside, do you think that could be causing the issue? I assumed it would just pass everything through to the Outside interface.

Thanks,

Isaac

So your VPN connects to the inside interface, then you're trying to connect to the outside interface? That won't work, and neither would it the other way round (VPN to outside, connect to inside). You have to connect to the nearest (inward) interface.

What are you using this ASA for? I'm puzzled.

We've been using the ASA as a firewall thus far but I'm trying use the VPN features.

I know it's strange to try to connect to VPN from inside the network, but I'm just testing things out. I can't make changes to the ASA from home without VPN access so all I can really do is go home, see it doesn't connect, tweak some settings the next day and repeat. It was pretty slow going so I tried opening it up on the Inside interface.

Anyway I got it straigthened out, our documentation of the ASA's interfaces was out of date, so I was connecting to the wrong interface. I got connected last night and everything works.

Thanks for your help, sorry for the confusion.

Isaac