<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 VPN Failover over WAN failover. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754650#M496189</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be also be possible to specfic different interfaces in the crypto map i.e. &lt;EM&gt;crypto map l2lsites interface outside and &lt;EM&gt;crypto map l2lsites interface outside2.&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;As the WAN failover would switch over to outside2?&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Oct 2011 16:02:01 GMT</pubDate>
    <dc:creator>John Peterson</dc:creator>
    <dc:date>2011-10-10T16:02:01Z</dc:date>
    <item>
      <title>ASA 5505 VPN Failover over WAN failover.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754648#M496187</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopeing someone can point me in the right direction, I have a ASA 5505 which is connected to a remote site which also has a ASA 5505 over a L2L VPN tunel. One of the sites has a WAN failover configured with two ISP which is working successfully. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, when the WAN connection fails over to the backup connection the VPN link breaks as the peer site IP address has changed and the VPN can not establish a connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be possible to configure a VPN failover so that when the connection failovers so will the VPN tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754648#M496187</guid>
      <dc:creator>John Peterson</dc:creator>
      <dc:date>2019-03-11T21:35:42Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 VPN Failover over WAN failover.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754649#M496188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you use the "crypto map &lt;MAPNAME&gt; &lt;INDEX number=""&gt;&amp;nbsp; set peer x.x.x.x" you can specify multiple peer IPs to use as a fallback list ie. it tries the first IP and if that fails then the next etc. So you could try - &lt;/INDEX&gt;&lt;/MAPNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;MAPNAME&gt; &lt;INDEX&gt; set peer x.x.x.x y.y.y.y&amp;nbsp; &amp;lt;--- where y.y.y.y is the backup Wan IP.&lt;/INDEX&gt;&lt;/MAPNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 15:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754649#M496188</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-10-10T15:40:42Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 VPN Failover over WAN failover.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754650#M496189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be also be possible to specfic different interfaces in the crypto map i.e. &lt;EM&gt;crypto map l2lsites interface outside and &lt;EM&gt;crypto map l2lsites interface outside2.&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;As the WAN failover would switch over to outside2?&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 16:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754650#M496189</guid>
      <dc:creator>John Peterson</dc:creator>
      <dc:date>2011-10-10T16:02:01Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 VPN Failover over WAN failover.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754651#M496190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can apply different crypto maps to different interfaces if that is what you are asking but you would need to make sure that if you wanted the traffic to go via outside2 for failover then traffic is routed that way on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 19:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754651#M496190</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-10-10T19:10:44Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 VPN Failover over WAN failover.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754652#M496191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;would the ASA choose the next interface is it can't connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking to do something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;crypto ipsec transform-set esp-3des-md5 esp-3des esp-md5-hmac&lt;BR /&gt; crypto map l2lsites 10 match address acl-l2l-ny&lt;BR /&gt; crypto map l2lsites 10 set peer XXX.XXX.XXX.XXX&lt;BR /&gt; crypto map l2lsites 10 set transform-set esp-3des-md5&lt;BR /&gt; crypto map l2lsites interface outside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;crypto map l2lsites interface outside_failover&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&lt;EM&gt;crypto isakmp enable &lt;EM&gt;outside&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&lt;EM&gt;&lt;EM&gt;&lt;EM&gt;&lt;EM&gt;&lt;EM&gt;crypto isakmp enable &lt;EM&gt;outside_failover&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In which case when the internet connection fails over the VPN the ASA would know that outside is down and then its try outside_failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm right in thinking this is how it would work?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 07:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754652#M496191</guid>
      <dc:creator>John Peterson</dc:creator>
      <dc:date>2011-10-11T07:08:39Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 VPN Failover over WAN failover.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754653#M496192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also how about the tunnel group?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 13:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754653#M496192</guid>
      <dc:creator>John Peterson</dc:creator>
      <dc:date>2011-10-12T13:21:21Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 VPN Failover over WAN failover.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754654#M496193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I managed to get it working, like so&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1 style="text-align: center; font-size: 20px; color: #000000; font-family: Verdana, Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;A href="http://www.petenetlive.com/KB/Article/0000544.htm"&gt;&lt;STRONG&gt;Cisco ASA/PIX 8.x: Redundant or Backup ISP Links&lt;/STRONG&gt; with VPNs&lt;/A&gt;&lt;/H1&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Dec 2011 15:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-vpn-failover-over-wan-failover/m-p/1754654#M496193</guid>
      <dc:creator>Peter Long</dc:creator>
      <dc:date>2011-12-12T15:02:52Z</dc:date>
    </item>
  </channel>
</rss>

