<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I do load-sharing on the ASA when using Site-to-Site VPN? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151312#M874801</link>
    <description>&lt;P&gt;I'm using ASA as a VPN concentrator on HQ site. I've used Public IP addresses on both interfaces,Inside and Outside interfaces. I've had 4 branch sites connecting to HQ using Site-to-Site VPN. How can I do load-sharing with those 2 interfaces on ASA? What I want to do is that 2 branch sites peer with the outside interface and the other 2 branch sites peer with the inside interface. Is this possible? If not,What's the best practice to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:07:37 GMT</pubDate>
    <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
    <dc:date>2019-03-11T15:07:37Z</dc:date>
    <item>
      <title>Can I do load-sharing on the ASA when using Site-to-Site VPN?</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151312#M874801</link>
      <description>&lt;P&gt;I'm using ASA as a VPN concentrator on HQ site. I've used Public IP addresses on both interfaces,Inside and Outside interfaces. I've had 4 branch sites connecting to HQ using Site-to-Site VPN. How can I do load-sharing with those 2 interfaces on ASA? What I want to do is that 2 branch sites peer with the outside interface and the other 2 branch sites peer with the inside interface. Is this possible? If not,What's the best practice to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151312#M874801</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2019-03-11T15:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151313#M874802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not load sharing.  Best practise is to have the VPN's terminate on the outside interface.  The ASA does not support Site-to-Site VPN load Balancing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 08:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151313#M874802</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-03-20T08:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151314#M874803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;   Thanks for the prompt. What I'm going to do at HQ site is as follows:&lt;/P&gt;&lt;P&gt;- I've got 2 WANs (2 ISPs)&lt;/P&gt;&lt;P&gt;- I've got a load balance box.&lt;/P&gt;&lt;P&gt;- I've got 2 Public IP Blocks from 2 ISPs&lt;/P&gt;&lt;P&gt;ASA--&amp;gt;Default Route--&amp;gt; LoadBalanceBox--&amp;gt; Separate 2 Wans(2 ISPs)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside(Untrust) interface will be assigned with the public ip address of ISP-A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside(Trust) interface will be assigned with the public ip address of ISP-B. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got 4 branch sites to do site-to-site VPN with HQ site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want the 2 branch sites to peer with the outside interface on the ASA (Via ISP-A).&lt;/P&gt;&lt;P&gt;I want the other 2 branch sites to peer with the inside interface on the ASA (Via ISP-B). But traffic will go from outside-to-inside. Is this allowed by ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopes I explained a bit more about my question in detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share what you guys think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 18:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151314#M874803</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-20T18:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151315#M874804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question - why do you want to terminate the VPN's on seperate interfaces, but allow them to commincate together?  You may as well just terminate them on 1 interface - then you have an interface to spare.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 19:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151315#M874804</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-03-20T19:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151316#M874805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;  That's why I called "Load-Sharing". I want to use 2 ISPs for peering IPSec VPN. Actually I can do NAT(udp/500,4500) on the device connecting to the ISP-A to terminate IPSec packet on the outside interface as the packets coming from the ISP-B. I just want to know that ASA allows us to do IPsec peer with the inside interface but packets coming from the outside interface or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Toshi &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 19:26:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151316#M874805</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-20T19:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151317#M874806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This isn't how I would implement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like you have two Provider Allocated (PA) IP ranges and therefore you require two interfaces with public IPs.  However I would configure two outside interfaces and IP your inside interface using private addressing. ie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; nameif ISP1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; 200.1.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; nameif ISP2&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; 195.1.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet4&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN traffic will be allowed to go from outside to inside if it's defined in the crypto ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are also lots of other designs you could do ie with a layer of routers and NAT or multi context mode ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 19:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151317#M874806</guid>
      <dc:creator>JamesLuther</dc:creator>
      <dc:date>2009-03-20T19:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151318#M874807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;   Thanks for that. The inside interface is connecting to all hosts assigned with the public ip addresses of ISP-A. This is the existing network. That's why I can't do 2 outside interfaces on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Toshi &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 19:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151318#M874807</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-20T19:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151319#M874808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How many interfaces does your device actually have?  I ask as if you use the inside interface for this task - how are you going to monitor/troubleshoit/configure the device?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 20:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151319#M874808</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-03-20T20:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151320#M874809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew,&lt;/P&gt;&lt;P&gt;  Don't get me wrong. I indeed have 2 interfaces,Outside and Inside. They both have been assigned with the different public ip addresses from the different ISPs. My question is "Does ASA allow us to use the inside interface to do IPSec peer with the other devices comming from the outside interface?".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Toshi &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 20:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151320#M874809</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-20T20:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can I do load-sharing on the ASA when using Site-to-Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151321#M874810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In theory - yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be alot easier though if you connected the outside interface to a switch - and a port that was a trunk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They you could create sub-interfaces of the outside interface, and give them the same security level - while allowing you to use the inside interface for management.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 21:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-do-load-sharing-on-the-asa-when-using-site-to-site-vpn/m-p/1151321#M874810</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-03-20T21:30:47Z</dc:date>
    </item>
  </channel>
</rss>

