cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
435
Views
0
Helpful
1
Replies

firewall replacement question?

Keith Craycraft
Level 1
Level 1

currently working on replacing firewalls with ASA's.

Question is it better to replace the hub site in a group of l2l vpn tunnels or do the end sites and then replace the hub site?

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

I would recommend that you replace your remote site first before replacing the hub.

Worst case scenario, if you replace the remote first, at least if it is not working, then you just have to concentrate to troubleshoot one remote L2L connection. If you replace the hub, and if it's not working, then you would need to troubleshoot all L2L tunnels to the remote.

I wouldn't think there would be much issue anyway replacing the firewall as IPSec standard is pretty mature by now, and most vendors IPSec are compatible with each other.

View solution in original post

1 Reply 1

Jennifer Halim
Cisco Employee
Cisco Employee

I would recommend that you replace your remote site first before replacing the hub.

Worst case scenario, if you replace the remote first, at least if it is not working, then you just have to concentrate to troubleshoot one remote L2L connection. If you replace the hub, and if it's not working, then you would need to troubleshoot all L2L tunnels to the remote.

I wouldn't think there would be much issue anyway replacing the firewall as IPSec standard is pretty mature by now, and most vendors IPSec are compatible with each other.

Review Cisco Networking for a $25 gift card