cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
497
Views
0
Helpful
2
Replies

ASA L2L spoke to Hub SFR firepower

keithcclark71
Level 3
Level 3

 I have 2 prev gen ASA 5505's connecting IPSEC IKE1 tunnels back to a single corporate ASA 5520. I am replacing the spoke site ASA 5505 with 5508-X and the Hub site 5520 to 5545-x. The  Esxi Virtual FMC will be located behind the Hub sites ASA 5545-x attached to VLAN on layer 3 core switch.   I am having hard time understanding how the newly placed 5508-x spokes will be able to send event traffic through the ASA5545-x into the FMC. I don't see how the SFR IP addresses in this particular toplogy can be on the same VLAN as the FMC as routing for this VLAN where FMC sits is defined at the HUB . Address space for the SFR would be overlapping the FMX?

Ex:

5508-x Spoke Site  SFR 192.168.23.10 (California)

FMC HUB 192.168.23.100  (Buffalo)

Suggestions anyone???

2 Replies 2

Philip D'Ath
VIP Alumni
VIP Alumni

In each asa. the SFR module IP address be on the local LAN (or wherever you physically plug the "management" port into).  The virtual management appliance will talk over your VPNs to the local management IP address.

ok so the SFR at these spoke sites will need to be of an address assignment pertaining to a local ASA interface and therefore would be a different subnet than that of the FMC. I was hoping for simplicity that I could have all Remote spoke  SFR IP's and FMC HUB IP all on same management subnet.

Review Cisco Networking for a $25 gift card