<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure ASAv Question involving VPN and a VIP address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784008#M1098232</link>
    <description>&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;I have come up with a solution to get my Corporate traffic into Azure by way of a VPN, which will terminate on a HA pair of ASAv firewalls. I need to protect an HTTPS flow within the tunnel and have it decrypted on the ASAv.&lt;/P&gt;&lt;P&gt;The flow would be our Corp network as src address range to a VIP that will sit on both ASAv firewalls. The VIP is from the Azure public address ranges and has been created in Azure. A NAT rule will essentially take that input and convert the destination IP address from the VIP to the internal ip address of our ALB within Azure.&lt;/P&gt;&lt;P&gt;I haven't tested this yet, but I can't see anything that would stop this working, as because the traffic is coming to the ASAv from a VPN tunnel, i don't need the ASAv to arp for the VIP.&lt;/P&gt;&lt;P&gt;What do you all think?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2023 12:13:23 GMT</pubDate>
    <dc:creator>jamesholley</dc:creator>
    <dc:date>2023-02-28T12:13:23Z</dc:date>
    <item>
      <title>Azure ASAv Question involving VPN and a VIP address</title>
      <link>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784008#M1098232</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;I have come up with a solution to get my Corporate traffic into Azure by way of a VPN, which will terminate on a HA pair of ASAv firewalls. I need to protect an HTTPS flow within the tunnel and have it decrypted on the ASAv.&lt;/P&gt;&lt;P&gt;The flow would be our Corp network as src address range to a VIP that will sit on both ASAv firewalls. The VIP is from the Azure public address ranges and has been created in Azure. A NAT rule will essentially take that input and convert the destination IP address from the VIP to the internal ip address of our ALB within Azure.&lt;/P&gt;&lt;P&gt;I haven't tested this yet, but I can't see anything that would stop this working, as because the traffic is coming to the ASAv from a VPN tunnel, i don't need the ASAv to arp for the VIP.&lt;/P&gt;&lt;P&gt;What do you all think?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 12:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784008#M1098232</guid>
      <dc:creator>jamesholley</dc:creator>
      <dc:date>2023-02-28T12:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ASAv Question involving VPN and a VIP address</title>
      <link>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784031#M1098233</link>
      <description>&lt;P&gt;seem like it will work so you have a ALB as public IP addresses. the vpn tunnel will formed from remote side to ASAv where as for the presentation of ASAv ALB will be the outside (let say the point where the traffic vpn will terminate). yes sound like it will work.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 12:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784031#M1098233</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2023-02-28T12:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ASAv Question involving VPN and a VIP address</title>
      <link>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784039#M1098234</link>
      <description>&lt;P&gt;Yes, the two ASAv are sat behind a PLB, which will pass IKE traffic through to the active ASAv.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 12:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784039#M1098234</guid>
      <dc:creator>jamesholley</dc:creator>
      <dc:date>2023-02-28T12:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ASAv Question involving VPN and a VIP address</title>
      <link>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784044#M1098236</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/111230"&gt;@jamesholley&lt;/a&gt; these two ASAv in ha pair? you mentioned the word active ASAv so i assume it HA pair. yes the sound of this would work.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 12:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784044#M1098236</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2023-02-28T12:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ASAv Question involving VPN and a VIP address</title>
      <link>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784049#M1098237</link>
      <description>&lt;P&gt;Hi, yes, an HA pair working in active/standby mode.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 13:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/azure-asav-question-involving-vpn-and-a-vip-address/m-p/4784049#M1098237</guid>
      <dc:creator>jamesholley</dc:creator>
      <dc:date>2023-02-28T13:02:57Z</dc:date>
    </item>
  </channel>
</rss>

