cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
452
Views
1
Helpful
1
Replies

ASA DVTI Dual Hub Setup, Configure spoke to prefer closer hub

dhau
Level 1
Level 1

I am preparing to implement site-to-site VPN across multiple firewalls located at two sites. I will be setting up 2 DVTI hubs, one hub for each site. I will set up the 2 DVTI hubs to be redundant to each other, so in the event that one hub goes down, all the other spokes will have a tunnel to the other DVTI hub and continue to encrypt spoke-to-spoke traffic. The way I am setting up this redundancy is by configuring each spoke firewall to connect to the HUB-A firewall and HUB-B firewall.

The sites are connected on the same network, but just geographically further, so I want to have spoke-to-spoke traffic within the same site to use the local site's hub firewall when both hub firewalls are up.

For example, if I had traffic between SPOKE-A1 and SPOKE-A2, I would like the DVTI traffic to prefer SPOKE-A1 -> HUB-A -> SPOKE-A2 instead of SPOKE-A1 -> HUB-B -> SPOKE-B.

I have been looking at EIGRP but the EIGRP implementation on ASA is limited and does not provide options to influence path selection like the routers. 

The implementation should not shutdown SPOKE-A1's tunnel to HUB-B, since there may be spoke to spoke traffic from Site A to Site B. For example, SPOKE-A1 -> HUB-B -> SPOKE-B1, or SPOKE-A1 -> HUB-A -> SPOKE-B1 (Tunnel is up between HUB-A and SPOKE-B1).

Would anybody have ideas on certain EIGRP configurations or any other supported dynamic routing protocol, or other implementation ideas, so that in normal operational state, 2 spokes located at the same site will use the local hub, instead of routing the traffic all the way to the other DVTI hub?

1 Reply 1

I will send to you PM check it

thanks 

MHM

Review Cisco Networking for a $25 gift card