monitor ASA5505 over site 2 site VPN tunnel

Unanswered Question
Mar 16th, 2010


We have a site to site VPN between a checkpoint and a asa5505. Everything is working fine. We would now like to monitor the asa5505 from our monitoring server which is behind the checkpoint.

I have configured the snmp community. When I check the log on the asa, I can see the request coming in from the monitoring machine and it is not being blocked. However, it is not working.

How can I fix/troubleshoot this issue?

Thanks in advance,


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Brandon Buffin Tue, 03/16/2010 - 13:16

Could be a routing issue. Can you ping the monitoring server from the ASA?


jeroenhermans Tue, 03/16/2010 - 14:31


Thanks for your reply. I cannot ping the monitoring server from the ASA. But I don't think it is related as I cannot ping anythng from the ASA, or anything that is behnd the asa cannot ping anything that is on the internet.I beleive this to be a seperate issue as the asa by default does not allow ping.

I can also not telnet or ssh to the asa via the vpn tunnel, this is probably the same issue as the snmp one.



Brandon Buffin Wed, 03/17/2010 - 06:14

Is the monitoring server on a subnet that the ASA has a route to? Can you allow pings temporarily to test connectivity?



This Discussion