12-21-2010 04:21 AM - edited 03-12-2019 06:01 PM
currently working on replacing firewalls with ASA's.
Question is it better to replace the hub site in a group of l2l vpn tunnels or do the end sites and then replace the hub site?
Solved! Go to Solution.
12-21-2010 04:36 AM
I would recommend that you replace your remote site first before replacing the hub.
Worst case scenario, if you replace the remote first, at least if it is not working, then you just have to concentrate to troubleshoot one remote L2L connection. If you replace the hub, and if it's not working, then you would need to troubleshoot all L2L tunnels to the remote.
I wouldn't think there would be much issue anyway replacing the firewall as IPSec standard is pretty mature by now, and most vendors IPSec are compatible with each other.
12-21-2010 04:36 AM
I would recommend that you replace your remote site first before replacing the hub.
Worst case scenario, if you replace the remote first, at least if it is not working, then you just have to concentrate to troubleshoot one remote L2L connection. If you replace the hub, and if it's not working, then you would need to troubleshoot all L2L tunnels to the remote.
I wouldn't think there would be much issue anyway replacing the firewall as IPSec standard is pretty mature by now, and most vendors IPSec are compatible with each other.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide