cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
395
Views
0
Helpful
6
Replies

Configure ASA for dedicated connection to main office and to the Internet

AMcMillon
Level 1
Level 1

Currently, our ASA 5512 is configured to route outbound traffic to the Internet and I need to be able to configure an additional uplink to a dedicated connection.  I have been using NAT for inbound access to servers over the current uplink.  Now, I need to add a second connection that will be a dedicated link to our main office.  I may still need to use NAT for inbound access over the Internet uplink; but, will not need to use NAT for the dedicated connection. 

 

Thanks,

 

Anthony McMillon

6 Replies 6

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi Anthony,

You can use policy-based routing for routing the traffic through the other link as you do not need NAT for the dedicated connection:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-based.pdf

Regards,

Aditya

Please rate helpful posts.

I didn't really see a question in your post.  What is the issue you are facing?

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

I just wanted some guidance on setting up the appliance to use a dedicated connection for communication to the main office as well as an Internet connection for allowing acces to remote desktops and possibly remote access for management. 

This second connection, what type of traffic will be going over it? is it just traffic to the main office?  Does the main office and remote office have different configured subnets?

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

chhayheng
Level 1
Level 1

Hi AMcMillon,

From my understand.

It is possible.

1. If the additional dedicate link is VPN. From the source to destination will lookup in your routing table, so it will route to main office.
2.  You can apply remote vpn internet interface.

http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/vpn/asa_91_vpn_config/vpn_ike.html

Best Regards,
Chhayheng

The VPN itself isn't an issue, but this will require static routes to work, so if there are some clients that will be accessing internet or other dynamically assigned addresses over the VPN then this will need to be taken into consideration.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card