networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Sat Sep 22, 2012 5:14 pm 
Offline
New Member
New Member

Joined: Sat Sep 22, 2012 4:52 pm
Posts: 2
Hi,

Me and my friend is currently setting up a Xen test environment.
As you can se from the picture below we are running a Cisco ASA 5505 to reach the network from the outside.
But the problem is that we want to reach the virtual pfSense's subnet's through the Cisco AnyConnect VPN.
And currently the pfSense's are only configured with a public ip and a virtual interface to the VM's.

We could be lazy and do a tunnel to the Cisco from each pfSense. I guess that could be a temporarily solution.
Or we could solve this problem by buying another PCI NIC, so that we have a physical link from the "pfSense box" to a tagged VLAN on the switch.
But we are having problems configuring the switch to general vlan's. Cause Xen can't have it's management interface on a tagged VLAN directly from the XenServer,
but the switch can tag the packet when it reaches the switchport.

Does anyone have any idea on how to solve this?

Image

I would like to have "switchport general allowed vlan 2" for admin and 10 for "LAN"
And then trunk the port to the Cisco ASA.

But again, Xen stops me from doing this.

:thankyou:

Regards.
Jonher937


Top
 Profile  
 
PostPosted: Sat Sep 22, 2012 10:49 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Nov 13, 2009 5:15 pm
Posts: 1947
Location: Pittsburgh
Certs: CCIE R&S,CCIP,JNCIA,VCP510
Maybe I am not understanding this correctly, but generally with a setup like this you would trunk that lan vlan into your hypervisor/Xen and run that vlan all the way up to the ASA. Within your ASA you would then allow split tunneling for that LAN segments so you would get both of your 172.20.x.x networks.

_________________
"I will prepare and some day my chance will come." - Abraham Lincoln
http://danielhertzberg.wordpress.com - I blog about networks!


Top
 Profile  
 
PostPosted: Sun Sep 23, 2012 12:03 pm 
Offline
New Member
New Member

Joined: Sat Sep 22, 2012 4:52 pm
Posts: 2
Thanks for your reply. I have tried trunking them, but without success. So I allowed VLAN 10 (LAN), 1 for Xen (Default VLAN) on both the XenPorts and the Cisco port. I even tried to configure the cisco interface as a trunk. No success there either. So now i've set a IP for the pfSense's on the LAN interface of the physical machines (172.20.20.X2)

Then I put a static route to both of the subnets, I can now ping all ip's on the pfSense subnets. Only thing that is left is setting up ACL's to be able to reach all networks over VPN.
I've tried many ACL's, then I gave up and tried Global (any to any).
The result when running "Packet trace" was: (acl-drop) flow is denied by configured rule

And I can't seem to figure out why....
I'm still very new to Cisco's ACL's and NAT's.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: wdmjr69 and 8 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group