I have an NMS in branch A that polls devices in branch B. The tunnel is up and I can ping across it, access the remote devices ASDM, even RDP into hosts at branch B.
But for whatever reason the ASA in branch A keeps denying the UDP port 161 traffic.
The default, out of the box ACLs are setup, with the addition of ICMP from outside to inside for testing.
Shouldn't all VPN traffic bypass ACLs becaues its on the tunnel, I shouldn't need ACLs to allow traffic from one side of the VPN to the other should I?
Log error message:
Deny inbound UDP from 192.168.200.228/1034 to 192.168.100.120/161 on interface outside
But for whatever reason the ASA in branch A keeps denying the UDP port 161 traffic.
The default, out of the box ACLs are setup, with the addition of ICMP from outside to inside for testing.
Shouldn't all VPN traffic bypass ACLs becaues its on the tunnel, I shouldn't need ACLs to allow traffic from one side of the VPN to the other should I?
Log error message:
Deny inbound UDP from 192.168.200.228/1034 to 192.168.100.120/161 on interface outside