Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Redundant VPN on ASA

Reply
Thread Tools

Redundant VPN on ASA

 
 
whatareyourmemes@hotmail.com
Guest
Posts: n/a
 
      06-12-2007
I am attempting to setup a redundant VPN solution utilizing the ASA
platform with the following layout.



RMT-ASA - originate-only w/ two peers
specified

l

CLOUD

/ \

RTR1 RTR2 - two disparate ISP T1 links to
the internet; primary and backup

\ /

HQASA - terminates L2L VPN with
connection type "answer-only"

l

HQRTR

l

LAN



My intention is to have the remote ASA (RMT-ASA) VPN connection
failover to the backup interface connection if the primary ISP link
fails - and then failback when it becomes available again.



HQASA is configured with SLA tracking on the default route for the
outside interface and a floating static for the backup interface. I
have tested to the point that when the primary connection fails the
VPN will shift to the backup connection without intervention.
However, if the primary link comes up the VPN will not "failback" and
because the SLA tracking on HQASA reinstates the "outside" interface
as the default route I lose all VPN connectivity. The remote ASA
seems to keep wanting to stick with the backup link as it continues to
try to connect with that peer IP.



Am I approaching this in the right way? First time working with ASA's.

 
Reply With Quote
 
 
 
 
Scott Perry
Guest
Posts: n/a
 
      06-12-2007
The Cisco ASA supports OSPF.

I suggest enabling OSPF between the ASA and the two Internet routers.
Configure the OSPF cost to the primary and secondary routers to give
preference as to which router should be used. In this setup, the primary
router will stop its advertisements when it either fails or loses its
Internet connection and the ASA will dynamically adjust to use the secondary
router. When the primary router returns to normal operation and advertises
the Internet route again with its preferred cost, the ASA will dynamically
adjust back to using the primary router.

===========
Scott Perry
===========
Indianapolis, Indiana
________________________________________

<> wrote in message
news: oups.com...
>I am attempting to setup a redundant VPN solution utilizing the ASA
> platform with the following layout.
>
>
>
> RMT-ASA - originate-only w/ two peers
> specified
>
> l
>
> CLOUD
>
> / \
>
> RTR1 RTR2 - two disparate ISP T1 links to
> the internet; primary and backup
>
> \ /
>
> HQASA - terminates L2L VPN with
> connection type "answer-only"
>
> l
>
> HQRTR
>
> l
>
> LAN
>
>
>
> My intention is to have the remote ASA (RMT-ASA) VPN connection
> failover to the backup interface connection if the primary ISP link
> fails - and then failback when it becomes available again.
>
>
>
> HQASA is configured with SLA tracking on the default route for the
> outside interface and a floating static for the backup interface. I
> have tested to the point that when the primary connection fails the
> VPN will shift to the backup connection without intervention.
> However, if the primary link comes up the VPN will not "failback" and
> because the SLA tracking on HQASA reinstates the "outside" interface
> as the default route I lose all VPN connectivity. The remote ASA
> seems to keep wanting to stick with the backup link as it continues to
> try to connect with that peer IP.
>
>
>
> Am I approaching this in the right way? First time working with ASA's.
>



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Redundant site to site vpn pix/asa v7.2.x jackwik@gmail.com Cisco 0 02-02-2008 05:03 PM
ASA 5505 as hardware vpn client to PIX 501 or ASA 5505 with network extension mode activated bjorn@kumlait.se Cisco 1 06-17-2007 12:43 PM
ASA 5520 Redundant Links Inbound/Outbound Nick Your Company Computer Guy Cisco 7 04-03-2007 11:59 PM
VPN to ASA from Cisco VPN Client Getting Error K.J. 44 Cisco 2 10-20-2006 08:22 PM
redundant switches / redundant server NICs Stuart Kendrick Cisco 4 08-10-2004 08:54 PM



Advertisments