Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

Bronze

VPN clients unable to ping devices in the management subnet

VPN clients are able to ping all devices on the network BUT those located in the management subnet. My ASA has a direct connection to the management interface and therefore the subnet.

1 ACCEPTED SOLUTION

Accepted Solutions
Bronze

Re: VPN clients unable to ping devices in the management subnet

Good one too, take it off (management-only)

and if you want to access the own firewall at management ip you have to issue the global command management-access management

12 REPLIES
Bronze

Re: VPN clients unable to ping devices in the management subnet

Hi,

Have you created an nat exempt for management network?

Bronze

Re: VPN clients unable to ping devices in the management subnet

thanks for the quick reply. I have the following nat exempt:

access-list nonat extended permit ip any 172.16.250.0 255.255.255.0

the subnet above is for the VPN clients.

Bronze

Re: VPN clients unable to ping devices in the management subnet

Even you though you have the permit any to XXX.XXX.XXX.XXX and the xxx is the vpn network you have to apply the nat exempt in the management interface, the exempt are not globaly aplied, it's for each interface, so if you have only one exempt created it's prety much the problem

Bronze

Re: VPN clients unable to ping devices in the management subnet

I am not sure that I am following you. Are you saying to add the following:

nat (management) 0 access-list nonat

or

nat (management) 1 access-list nonat

Bronze

Re: VPN clients unable to ping devices in the management subnet

nat (management) 0 access-list nonat And if you have an split tunnel at the tunnel you have to put the management network to be tunneled, you can verify that at the client when you connect. you can right cliek the lock icon go to statistics than route and see which networks are going through the tunnel.

Bronze

Re: VPN clients unable to ping devices in the management subnet

Thanks. However, that did not work.

Bronze

Re: VPN clients unable to ping devices in the management subnet

It should!

Green

Re: VPN clients unable to ping devices in the management subnet

Is the interface management-only?

Bronze

Re: VPN clients unable to ping devices in the management subnet

Yes, the interface is management only.

nameif management

security-level 100

ip address 10.0.255.251 255.255.255.0 standby 10.0.255.252

management-only

Bronze

Re: VPN clients unable to ping devices in the management subnet

Good one too, take it off (management-only)

and if you want to access the own firewall at management ip you have to issue the global command management-access management

Bronze

Re: VPN clients unable to ping devices in the management subnet

Thanks much both for your inputs.

Green

Re: VPN clients unable to ping devices in the management subnet

I thought I brought up the "management-only"?

189
Views
4
Helpful
12
Replies
CreatePlease login to create content