cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
530
Views
0
Helpful
2
Replies

Establishing Outbound IPSec -VPN connections using Cisco virtual firewall services from the AWS Store / Market place

nyju.s007
Level 1
Level 1

Hi, We are in the process of establishing IPSec VPN connections from AWS through Cisco Virtual services. Device/Services should be,

  • IPSec capable  Customer-Premises Equipment (CPE); in our case  it is the Cisco device /service  we choose from AWS Market place
  • CPE must be licensed to accommodate DES, 3DES or AES encryption standards.
  • Following services needs to be open bi-directional between the VPN peers (TR Hosting VPN hub site peers & Client premises VPN device);
    •  IKE, ISAKMP, udp/500, AH, echo, echo-reply

We already have applications deployed in AWS and now need to connect to a third-party market data service provider through IPSec VPN.  The thirdparty Data Service Prvider has a Cisco ASA 5520 at their end and expecting us to initiate the VPN outbound connection through Cisco device. I have read through the options  (https://aws.amazon.com/marketplace/search?page=1&searchTerms=Cisco. ) of Cisco devices and found that CSR and ASAv options suits to our requuirement. However, bit confused with whether to choose CSR or ASAv. Requirement is simple IPSec VPN outbound connection initiated from AWS side. Should ASAv sufficient for this?

in case of ASAv option , Cisco Adaptive Security Virtual Appliance (ASAv) -Standard Package (https://aws.amazon.com/marketplace/pp/B00WH2LGM0/ref=srh_res_product_title?ie=UTF8&sr=0-6&qid=1448948798404  ) does not talk about IPSec VPN. Does this support IPSec VPN?

2 Replies 2

Philip D'Ath
VIP Alumni
VIP Alumni

Typically we just use Ubuntu and StrongSwan for this.  I found this guide.  We don't normally bother with iptables though (leave it turned off).

https://wiki.strongswan.org/projects/strongswan/wiki/AwsVpc

Philip D'Ath
VIP Alumni
VIP Alumni

ps.  The CSR1000V does support IPSec.  I don't think that the ASAv does.