07-18-2012 09:22 PM - edited 03-11-2019 04:32 PM
Hi,
I have 2xASA5510 with securityPlus licence.i have confugured 3 context and Active/Active Failover.Everything works fine. But also want to use rometeAccessVPN but couldn't fine anything for VPN. does it support VPN in multiple mode?Could you offer something?
Solved! Go to Solution.
07-18-2012 09:59 PM
No, VPN is not supported in multi context mode.
Here is the documentation for your reference:
http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/mode_contexts.html#wp1188973
07-19-2012 05:58 AM
I've heard that L2L VPN might become possible for multiple context mode ASAs in the future.
But VPN Client isnt either coming at all or is coming much later.
Its shame that this possiblity doesnt exist on the ASAs running multiple firewalls. It basically means you need a totally different equipment for VPN capabilites. And even then it means you have no way of virtualizing routing which again means you cant have overlapping networks on your ASA that you have dedicated only for VPN purposes.
This is especially bad when youre trying to move away from IOS VPN setups with old 6500 modules where you could use VRF:s for each VPN connection which totally eliminated the problem of overlapping networks. Configuring those VPNs to a single ASA becomes harder if you happen to have overlapping networks. (vpn pools, customer networks, L2L VPN remote networks)
- Jouni
07-19-2012 06:55 AM
07-18-2012 09:59 PM
No, VPN is not supported in multi context mode.
Here is the documentation for your reference:
http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/mode_contexts.html#wp1188973
07-19-2012 05:58 AM
I've heard that L2L VPN might become possible for multiple context mode ASAs in the future.
But VPN Client isnt either coming at all or is coming much later.
Its shame that this possiblity doesnt exist on the ASAs running multiple firewalls. It basically means you need a totally different equipment for VPN capabilites. And even then it means you have no way of virtualizing routing which again means you cant have overlapping networks on your ASA that you have dedicated only for VPN purposes.
This is especially bad when youre trying to move away from IOS VPN setups with old 6500 modules where you could use VRF:s for each VPN connection which totally eliminated the problem of overlapping networks. Configuring those VPNs to a single ASA becomes harder if you happen to have overlapping networks. (vpn pools, customer networks, L2L VPN remote networks)
- Jouni
07-19-2012 06:55 AM
01-21-2014 06:37 AM
For future reference..
Multi-context and dynamic routing are supported on v9 of ASA code and above (with the exception of the ASA 5505 and the Cisco Catalyst 6500 Series ASA Services Module).
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps12726/data_sheet_c78-714849.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide