VPN SSL from the inside on the external interface

Hi all

First of all I know that I can activate the SSL interface inside, but that's not what I need or want.

Scenario:

Several interfaces and VLAN on the SAA (running 8.0.5).

SSL VPN configured and enabled on the external interface.

Need to know if it is possible to access the SSL VPN from other interfaces directly to the IP address external interface, something like her hairpin.

Possible a solution (if it exists) with or without NAT (I have public IPs on some interfaces).

This will be useful for users who can connect any interface (inside, outside, or other) and with only a DNS record, I'll be able to manage everything.

Concerning

PS: Is DNS doctoring an option? The tests that I have done this does not work.

Post edited by: rcordeiro

Hello

Unfortunately, it is not possible. You cannot communicate with an ASA interface which is not directly connected through the firewall.

Kind regards

NT

Tags: Cisco Security

Similar Questions

  • No not removed from the external interface access-list access list?

    PIX515

    customer wanted to modify the access list (add a new line)

    so he has first publish no access-list command can

    apply the change to the access list, but the access list has been

    removed from the interface outside

    is this a normal behavior? on routers access list stay connected

    for the event of the interface if you issue no access-list command

    Thanks in advance for any comments

    JYP

    Hi Thibault-

    No, it is not a normal behavior, sounds more like an error by the customer. It's always a good idea to copy the required ACL on a text editor (Notepad) do not forget to include "access-group command" i.e. "access-group interface inside inside' or 'access-group out in interface outside' - when copying the required ACL and then issues a 'no access-list inside' or 'no access-list outside' the first line in the ACL copied on your notebook before copy you it to the PIX , also make sure that you are using the config and make an "m wr" (write memory) after the ACL modified have been applied on the PIX.

    Hope this helps-

  • Can't ssh on pix from the external interface

    I am using s/w ver 7.0 (4).

    The config for ssh is:

    generate crypto module rsa keys 1024

    WR mem

    SSH a.b.c.d 255.255.255.255 outside

    but it does not work.

    Help, please

    Yes, if your external interface is mapped to y.y.y.y, then you will be not able to ssh to x.x.x.x as it will be pass on to y.y.y.y.

    You can change the static 1 to 1 to the port for each particular port address translation you need sent to y.y.y.y.

    Please evaluate the useful messages.

  • Static and VPN on the external interface

    Hello

    Can someone tell me if it is possible (and if so, how) do vpn enabled on the external interface and to have something like:

    public static x.x.x.x interface (indoor, outdoor)

    IE: I have two addresses ip - one for the router an e0 on the pix. I create a static and lists of access to allow inbound http/https server inside but I also want to allow vpn hit e0 and work. My configs work if I use an ip address 3 for the static, but not if they share. I can imagine that the static method takes the vpn traffic before the pix can use it OR maybe as the pix has no route to the now (due to the static method) that it cannot answer?

    Hope I'm making sense

    Thanks for the time spent on this

    see you soon

    Andy

    I think you want something like this:

    public static tcp (indoor, outdoor) interface http 10.10.10.10 http netmask 255.255.255.255 0 0 (where 10.10.10.10 is your web server)

    public static tcp (indoor, outdoor) interface https 10.10.10.10 https netmask 255.255.255.255 0 0

    access-list 101 permit tcp any host x.x.x.x eq 80 (where x.x.x.x is your IP interface)

    access-list 101 permit tcp any host x.x.x.x eq 443

    Access-group 101 in external interface

    It will be useful.

    Steve

  • VPN client and ssh to the external interface of the ASA

    Hello world

    I was testing clientless ssl in my lab at home.

    When you're connected via vpn without customer, I am able to ssh ASA outside interface, but when I use ssl vpn only I can't ssh to the external interface of the ASA.

    Need to figure out how I can ssh to the external interface of the ASA using clientless ssl vpn?

    Concerning

    MAhesh

    Mahesh,

    When you are on clientless SSL VPN to your customer is not limited routes of the Internet, isn't being NATted etc. If ASA is set to allow ssh from outside, then the VPN SSL without client user is no different from any other.

    A the user SSL VPN full tunnel can have any or all of these factors at play. One of them can cause the impossibility to access the ASA outside interface via ssh. I see the configuration to tell you which one (or more) is to blame.

  • Network for access to the external interface inside

    Hey,.

    I have an ASA5520 7.2 (1) I have a few probs with - which is something I struggle with that.

    I'm trying to hit a website of a host on the inside network that is actually hosted internally, but decides the static NAT would focus on the external interface of the firewall.

    Now I can see the TCP built, translation occurring at a port on the external interface, this port high dialogue to one of the static electricity would be addresses on the external interface, then that's all. There are no more entries in my journal in regards to the connection and I get not syn on the internal web server is so the connection is not back in.

    IP address outside 222.x.x.9 255.255.255.248

    IP address inside 192.168.87.1 255.255.255.0

    Static NAT to Web servers: -.

    public static 222.x.x.10 (Interior, exterior) 192.168.87.5

    access lists access... :-

    list of allowed inbound tcp extended access any host 192.168.87.5 eq http

    Access-group interface incoming outside in

    Everything works fine when creating a global internet address - just not when address from inside and dynamic PAT is performed to the original address.

    Here's a capture session by using the following access to capture list inside and outside interfaces simultaneously

    permit for line of web access-list 1 scope ip host 222.222.222.10 all

    web access-list extended 2 line ip allow any host 222.222.222.10

    on the INSIDE interface (nothing is connected to the outside) (ip addresses have been replaced by nonsense) - but address 222 is would take into account the interface static and the other is on the internal network.

    316: 19:14:02.900206 192.168.87.10.2275 > 222.222.222.10.80: S 2029971541:2029971541 (0) win 64512

    317: 19:14:05.973185 192.168.87.10.2275 > 222.222.222.10.80: S 2029971541:2029971541 (0) win 64512

    192.168.87.10 is my client is trying to connect

    Someone of any witch hunt, which is stop this function work?

    All networks are directly attached and there is no route summary ancestral anywhere.

    I hope you guys can help!

    Concerning

    Paul.

    To my knowledge the ASA supports only hairpining on a VPN tunnel. The security apparatus does not allow traffic that is sent to an interface to go back in the direction of what she received.

  • HP personal media drive hp0000: remove the hard drive from the external area.

    My external hard drive does not work and I would like to remove the drive from the external hard drive case.  How to open the short cut through the plastic box?  I have other cases of emjpty for the hard drive.

    Access to the internal hard drive: methods and variants

    (1) open the support HP Pocket Drive is as simple as peel back label hardened plastic on the end of usb connection and to extract both little phillip screws hidden. Once the removed screws the drive carrier will slide on the front of the case and the hard drive can be easily replaced.

    (2) the same video

    (3) it is very easy to detach. With a small flat screwdriver take the label on the back cover. This will reveal the 2 small Phillips head screw. Remove them and gently pull the back cover. Then gently push all inside the well hard drive that forward into the aluminum housing. Careful not to push the reader through the case and on the floor.

  • Transfer the virtual machine from the external drive - URGENT HELP PLEASE

    I recently transferred my Virtual Machine to a hard drive external that I had to reinstall my OS Leopard, now when I try to copy the VM back to my mac from the external hard drive, to halfway through I have error message... "You cannot copy"Windows Vista.vmwarevm"because it has the same name as another article on volume of destination, and that the volume is not making the distinction between upper and lower case in file names."

    Virtual machine worked well for the external hard drive, but it's not convenient for me and I need ideally on my laptop... Please notify.

    To this folder on the Mac you copy it and what else is in this folder when copy you it.  I hope also merger is closed when you try to copy.

    Another thing you can do is inside the packaging of the Virtual Machine, there are two folders, Applications, and appListCache, I always delete before copy/move and these will be recreated and the reason why I do it, it is I saw copy fail until they have been deleted, although generally, it is one of the app in the Applications folder with the module of Virtual Machine that caused the problem.

    VMware Fusion (menu bar) > help > Search > type Package and then select work with Virtual Machine packages

  • Of failure, white screen MacBook Pro HARD drive try to boot from the external HARD drive

    Hello

    I have a 2008 Macbook Pro which is having some problems, I was able to fix them, but eventually the hard drive failed. I know that because at startup until it would have a white screen Uni (no logo) and you can hear a clicking on in the lower left corner. I thought initially it was a memory problem, but after opening and verification of memory, it's clearly the hard drive.

    I solved this problem temporarily (until I can replace the HARD disk) by installing El captain on an external HARD disc and start from that. Here's the twist, I couldn't he can begin to El captain, I tried CMD + R, CMD + OPT + R, CMD + OPT + R + P and now shift. Everything that's happened would be that clicks would cease to release the keys.

    I left the macbook on while I'm at work, when I got home it was on the screen to connect the external HARD drive.

    I accidentally closed the macbook yesterday and again once when I tried to log on, I could not and I left it on a white screen while I was sleeping. There is a possibility that he may have launched from the HARD drive when I get home, but if not, is there something that escapes me to force do this?

    See you soon

    Usually start up to a blank screen without the Apple Logo, may report one of the following:

    • Hardware failure
    • Boot drive is not recognized as valid and updated updated
    • OS X essential software is missing, hurt moved or renamed or corrupt
    • A firmware update is necessary

    No matter who, in order to boot from an external drive "bootable", you would normally hold down the Option key until you get a screen that offers a number of devices to try to boot from.

    Alternatively, you can try holding down the C key to try to boot from the external drive.

    If none of these startup options work, then the bootable disc or the USB port on your MacBook Pro can be the question.

    Since you have a Mac pre-2013, if you hold down the D key while booting, the built-in Apple Hardware Test should start up.  This can help to identify hardware problems.

  • reformatted my mac pro. copied from iPhoto from the external backup drive. received the error message saying lack of theme fonts. removed the app to be able to reinstall. but my app store it shows as installed. How I install it again.

    reformatted my mac pro. copied from iPhoto from the external backup drive. received the error message saying lack of theme fonts. removed the app to be able to reinstall. but my app store it shows as installed. How I install it again. the deleted copy is missing in the trash folder too.

    Unplug your backup disk, restart, and try again.

  • OS to boot from the external drive

    So I searched high and low, and I don't know if the Toshiba Satillite are able to start an operating system on an external hard drive. I discovered that there are portable computers that can do but their BIOS must beable to do. If Toshiba laptops can do those who can?

    Hello

    As far as I know it of not possible to boot from the external USB HDD.
    I found several postings on similar themes and it seems that it is only possible to boot from the external USB FDD, HDD, ODD and LAN are sometimes also PCMCIA card.

  • I have no sound from the external speaker

    I connected this morning my iPod in my car, as always. But today I got the only sound from the internal speaker and no sound from the external speaker in the car. So far I have never had problems.

    How did the car system connected to the car?

  • Portege R100 - boot from the external HARD drive

    I have a Portege R100 and the HARD drive has failed. I installed a new HARD drive and I have the Toshiba recovery disks. I tried to boot from a generic USB CD-ROM but the laptop did not recognize.

    I have a disk of Toshiba USB drive it does not recognize and I have a restore disc but I don't know how from there. Do I have to buy a CD external Toshiba and if so, which?
    Any useful suggestions?

    Hello

    Boot from the external USB CD/DVD drive is not possible.
    You will also be able to boot from USB HDD!

    If you want to boot from the CD, you must use a compatible PCMCIA cards (16-bit and 32-bit Cardbus) CD/DVD drive.

    For more information, see this article from Toshiba:
    http://support.toshiba-tro.de/KB0/TSB5100S70004R01.htm

    and this other thread:
    http://forums.computers.Toshiba-Europe.com/forums/thread.jspa?MessageID=97343𗰿
    http://forums.computers.Toshiba-Europe.com/forums/thread.jspa?threadID=8991&MessageID=31246

    Good bye

  • I spilled coffee on my Macbook Air and does not illuminate.  How to transfer files from the external hard drive to backup my new Macbook Air?

    I spilled coffee on my Macbook Air and does not illuminate.  How to transfer files from the external hard drive to backup my new Macbook Air?

    If you had a Time Machine backup, you can use the Migration Wizard and connect your new Mac on the external drive which has the Time Machine backup: move your content to a new Mac - Apple Support

  • Computer tries to boot from the external drive

    I use a desktop computer with Windows 7.  I have an external hard drive connected as a backup drive.

    While booting, the computer tries to boot from the external drive and nothing happens.

    In order to get the machine to start, I have to unplug the drive hard Ext., which is a waste of time.

    I would like to back up on the drive internally the computer c:

    Is there a way I can stop trying to boot from the external drive?

    At the start of the pc, open the BIOS, usually output tab, search (priority boot device), set C: 1st, 2nd or 3rd external

    Save and exit. Also, more need of HDs to put in shape before using it, most come in a "raw" State the mfg

Maybe you are looking for