Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Unable to access internal lan instance from remote vpn instance


Key players: : Corporate machine. : Cisco 881 configured to act as our tunnel to the remote data centre. : Cisco 5510 is our corporate LAN gateway and access to the outside world. : A machine at the remote end of the VPN that I can ssh into but cannot ssh back from.

I have a VPN configured to another data centre. It works successfully in the sense that I can ssh from my internal corporate network (10.10/16) to a remote instance (172.16/16). The configuration is like this: -> Cisco 881 ( : tunnel provision) -> Cisco ASA 5510 ( -> Internet -> Remote VPN Gateway ->

However, I cannot ssh *back* from to an instance on my local network, i.e.: -> Remote VPN Gateway -> Internet -> Cisco ASA 5510 ( -> Cisco 881 ( : tunnel provision) -> FAIL

I *can* ping the Cisco 881, i.e.,

Pinging *from* *to* I get an echo reply.

If I try to ping anything else (and by extension ssh as described above), it does not work (i.e., ping or ssh

This is really confusing me.

My thought would have been that as soon as traffic comes from to the Cisco 881, it decrypts it and then simply forwards the encapsulated packet on to via our gateway (

Anyone got any thoughts on this?

Thank you!


Everyone's tags (5)
CreatePlease login to create content