05-23-2019 05:21 AM
Hi everyone,
I would like to know what would be the impacts of adding many subnets to crypto map ACLs for Site-to-site VPN.
Currently HQ and new branch office is connected with IPsec site-to-site VPN over internet.
I would like New branch to have access to other branch offices through HQ.
I know it would work if I added the branch offices subnets to the current crypto map ACLs but I do not know the impact of adding many subnets to a crypto map ACL to route traffic over site-to-site VPN.
the number of subnets that I would like to add is about 20 subnets.
I am hoping stability and performance will be same as current Site-to-site VPN setting.
Can anyone please tell me your thoughts?
I attached a diagram that is simple and small version of what I want to do.
Best regards,
Tats
Solved! Go to Solution.
05-23-2019 06:07 AM
05-23-2019 05:39 AM
Have you considered using DMVPN as an alternative. That way you could treat it as routed traffic and have it participate in OSPF with your other locaitons. You could choose to run the tunnel in gre multi-point to allow spoke-to-spoke communications if you add other VPN branches in the future or leave it as point-to-point to force all traffic back through the hub. If you add other locations in the future there wouldn't be any need to change the configuration on the HQ hub, only add the needed configuration on the new branch router that you deploy.
05-23-2019 06:32 AM
Hi Lyle,
Thanks for your reply.
No we have not considered DMVPN as I am quite new to network stuff and do not know much about DMVPN. Also we are using Meraki MX68 at NewBranch and I saw MX68 only support ikev1 IPsec VPN only with non-Meraki device in a documentation.
But your suggestion sounds nice and clean if we would open other new branches in the future.
Thanks,
Tats
05-23-2019 06:07 AM
05-23-2019 07:22 AM
Hi GRANT3779,
Thanks for your reply.
That is good to hear that there is no real impact.
I am running an ASA at HQ and Meraki MX68 at NewBranch. Basically ikev1 IPsec vpn is the only choice.
Thanks,
Tats
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide