cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
849
Views
0
Helpful
1
Replies

site to site VPN peer ip address for failover

vinodk_gupta
Level 1
Level 1

Hi,

while creating site to site VPN/IPSec Tunnel on cisco ASA, can we put two peer ip address, one will be primary & other ip wiil be secondary when primary ip will not rechable.

1 Reply 1

You are probably not talking about an ASA-FO-system? There you don't need to configure two peers as the ip address will move to the secondary ASA when the primary fails.

If the two peers are individual boxes, then you can specify two peers in the "set peer" statement of your crypto map. If you use Pre-Shared-Keys, then you also have to configure a second tunnel-group for the backup-peer.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Review Cisco Networking products for a $25 gift card