01-19-2023 03:40 AM
A client of mine has a Cisco ASA that's currently running on multi context mode and needs to configure a site to site VPN to his AWS VPC. Kindly advise how to go about this as VTI is not supported on ASA in multi context mode.
Solved! Go to Solution.
01-19-2023 07:29 AM
A VTI (route-based) VPN is not required. You can use an "old school" policy-based VPN with crypto maps on the ASA.
You don't get the routing and (no) NAT simplicity of a VTI-based one, but it still works.
01-19-2023 04:16 AM
01-19-2023 05:28 AM
Thank you for the prompt response. However, the article was not very helpful as it has a note at the top that says "Note: Currently VTI is only supported in single-context, routed mode" . This is exactly what I am searching for a walk-around for. ASA mutli-context mode does not support VTI and to the best of my knowledge I need VTI to setup AWS S2S VPN.
01-19-2023 07:29 AM
A VTI (route-based) VPN is not required. You can use an "old school" policy-based VPN with crypto maps on the ASA.
You don't get the routing and (no) NAT simplicity of a VTI-based one, but it still works.
01-19-2023 07:32 AM - edited 01-19-2023 07:36 AM
Thank you. I thought about it earlier but I was confused as AWS does not have a policy based configuration file for ASA. I was later able to see a guide online and it works.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide