cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1393
Views
0
Helpful
8
Replies

SSH and ASDM to Pix over VPN Client Connection

cslitb
Level 1
Level 1

How can we setup access to manage the pix (ssh and asdm) over a vpn client connection? We have given access to the pix via ssh and asdm to the VPN sunbet, but cannot access the pix. The commands we entered are below:

ssh 111.111.111.0 255.255.255.0 outside

http 111.111.111.0 255.255.255.0 outside

111.111.111.0 255.255.255.0 is our VPN subnet

Any ideas would be great. Thanks

8 Replies 8

Farrukh Haroon
VIP Alumni
VIP Alumni

Are you using any split tunneling for the VPN connections, Or perhaps a vpn-filter?

After your VPN is established, what error do you see to get SSH/ASDM working?

Also have a look at the 'management-access' command:

http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/m_711.html#wp1631964

Regards

Farrukh

Yes, we are using split tunneling. The subnet for the inside interface of the pix is 192.168.0.0. We can get to other devices on that same subnet (webservers, dns, etc) using the vpn client, but cannot access the pix with SSH or asdm. We have looked at the syslogs, but do not see anything out of the ordinary.

Did you try the management-access command?

Regards

Farrukh

Currently we have this in our config:

http server enable

http 111.111.111.0 255.255.255.0 inside (tried both inside & outside)

management-access inside

This might be a stupid question, but have you tried ASDM/SSH from the inside (normal LAN users)? just to make sure all is well (Crypto keys, ASDM image etc.)

Regards

Farrukh

Yes we have. We can both SSH and ASDM access to the Pix from the "inside".

does the vpn not come in on the outside interface?

Yes, it does terminate on the outside interface.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: