Cisco ASA U-Turn traffic.
Our goal today is to remotely log in to ASA8 using Cisco anyconnect, and then connect to 10.2.0.10 behind ASA9 via IPSEC × ×.
1 the first picture is the schematic diagram
2 the second is the eve-ng network diagram. × × customers will remotely log in to ASA8 from net, that is, one of my virtual machines (with anyconnect × ×)
The remote user connects to the ASA8 and gets the address of the (10.255.255.X) segment
ASA8 (10.1.0.0amp 24)-IPSEC × ×-ASA9 (10.2.0.0Univer 24)
Configuration of ASA8
Object-group network IPSEC-AMAZON-LOCAL
Network-object 10.1.0.0 255.255.255.0
Network-object 10.255.255.0 255.255.255.0 ipconfig connects to a specific DNS suffix. . . . . . . :
Local link IPv6 address. . . . . . . . : fe80::3bbe:aded:4d75:973a%29
Local link IPv6 address. . . . . . . . : fe80::71da:6be3:37d2:b4b8%29
IPv4 address. . . . . . . . . . . . : 10.255.255.1 ping 10.2.0.10 is Ping 10.2.0.10 with 32 bytes of data:
Request timed out.
Reply from 10.2.0.10: byte = 32 time = 6ms TTL=64
Reply from 10.2.0.10: byte = 32 time = 3ms TTL=64
Reply from 10.2.0.10: byte = 32 time = Ping statistics for 3ms TTL=6410.2.0.10:
Packet: sent = 4, received = 3, lost = 1 (25% lost)
Estimated time for round trip (in milliseconds):
Shortest = 3ms, longest = 6ms, average = 4ms
C:\ Users\ Administrator > ping 10.1.0.10 is Ping 10.1.0.10 with 32 bytes of data:
Reply from 10.1.0.10: byte = 32 time = 4ms TTL=64