<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA VPN question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124355#M896194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well my question actually was to seperate only VPN traffic to a different interface.  I have a /24 block of IPs from our ISP, so this second interface would still go through the same ISP but have a differnet IP address.  Then I'd set up DNS to point to that IP for VPN only.  All outbound internet trafffic (and other inbound traffic like mail) would still go through the other primary interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Sep 2008 12:46:35 GMT</pubDate>
    <dc:creator>niro</dc:creator>
    <dc:date>2008-09-22T12:46:35Z</dc:date>
    <item>
      <title>ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124347#M896177</link>
      <description>&lt;P&gt;I'm getting ready to move our VPN connections from the VPN Concentrator to our ASA which is also our internet firewall.  My question is, does it make sense to connect one of the ASA's unused ports to the DMZ and use that as the VPN port or just configure VPN to come in to the outside interface (which is already plugged in to the DMZ anyway)?  My thought was to plug in a new port with a new IP to keep VPN traffic seperate from other internet traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:46:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124347#M896177</guid>
      <dc:creator>niro</dc:creator>
      <dc:date>2019-03-11T13:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124348#M896179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is depends if u have another ISP connection !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if u have two ISPs u can make two interfaces and give vpn users the secondary ISP public IP and use the primary one for outbound internet traffic&lt;/P&gt;&lt;P&gt;but if u have only one interface with one ISP &lt;/P&gt;&lt;P&gt;u must use only ur outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if helpful Rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Sep 2008 10:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124348#M896179</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-20T10:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124349#M896181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marwanshawi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you ever implemented this in a production &lt;/P&gt;&lt;P&gt;environment and that it works without any &lt;/P&gt;&lt;P&gt;glitches?  I am interested to know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Sep 2008 13:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124349#M896181</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-09-20T13:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124350#M896187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi david &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the idea is &lt;/P&gt;&lt;P&gt;lets say u have two ISPs connections &lt;/P&gt;&lt;P&gt;we know with ASA we cant do loadbalancing but we can make links work in primary and backup manaer&lt;/P&gt;&lt;P&gt;u can u se ISP1 as the exit point for outbound traffic throut for example&lt;/P&gt;&lt;P&gt;route outside 0 0 [ISP1]&lt;/P&gt;&lt;P&gt;route outside2 0 0 [ISP] [higher metric]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now ISP1 prefered &lt;/P&gt;&lt;P&gt;if goes down ISP2 will be used&lt;/P&gt;&lt;P&gt;for load sharing u can but not must &lt;/P&gt;&lt;P&gt;give the VPN users the public IP address of the link with ISP2&lt;/P&gt;&lt;P&gt;in the case lets say both ISP links operational then outbound traffic will be through ISP1 and VPN through ISP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which is good &lt;/P&gt;&lt;P&gt;but if u have one link i mean one exit point to the internet you wont be able to impliment it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the link for ASA with two ISPs:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;P&gt;if helpful Rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Sep 2008 13:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124350#M896187</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-20T13:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124351#M896189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am very well aware of this. But the question&lt;/P&gt;&lt;P&gt;he asked is that he want to separate VPN users&lt;/P&gt;&lt;P&gt;traffics from other Internet traffics.  By that,&lt;/P&gt;&lt;P&gt;I assume he means "inbound" traffics.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, he want "inbound" internet&lt;/P&gt;&lt;P&gt;traffics to use the primary link while the VPN &lt;/P&gt;&lt;P&gt;users will be using secondary link for &lt;/P&gt;&lt;P&gt;"inbound"' VPN traffics?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just dont see how that is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link you described is for outbound &lt;/P&gt;&lt;P&gt;traffics.  VPN traffics is inbound.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Sep 2008 14:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124351#M896189</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-09-20T14:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124352#M896191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the link is the half way&lt;/P&gt;&lt;P&gt;the link let u configure the redandunt links&lt;/P&gt;&lt;P&gt;then u need to setup the vpn and use the secondary interface for the vpn and give the vpn client the secondary public ip address in this case the vpn inbound and communication will be through the secondary ISP (interface) while other traffic like outbound intternet will be normaly through the primary and if the primary gos down will be through the secondary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this time clear &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Sep 2008 14:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124352#M896191</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-20T14:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124353#M896192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That goes back to the question I had before.  &lt;/P&gt;&lt;P&gt;Have you implemented this in a production &lt;/P&gt;&lt;P&gt;network and that it works without any glitches?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very skeptical of these configurations and&lt;/P&gt;&lt;P&gt;that I am sure there are lot of caveats that&lt;/P&gt;&lt;P&gt;will come with this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Sep 2008 14:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124353#M896192</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-09-20T14:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124354#M896193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Sep 2008 14:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124354#M896193</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-20T14:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124355#M896194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well my question actually was to seperate only VPN traffic to a different interface.  I have a /24 block of IPs from our ISP, so this second interface would still go through the same ISP but have a differnet IP address.  Then I'd set up DNS to point to that IP for VPN only.  All outbound internet trafffic (and other inbound traffic like mail) would still go through the other primary interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2008 12:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/1124355#M896194</guid>
      <dc:creator>niro</dc:creator>
      <dc:date>2008-09-22T12:46:35Z</dc:date>
    </item>
  </channel>
</rss>

