cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
460
Views
0
Helpful
1
Replies

EOMPLS via ASA

tshibos
Level 1
Level 1

I am trying to build an EoMPLS connection between 2 sites via 2 ASA on each site. The goal to is to extend 1 or more VLAN between sites. It has been deployed successfully in the past without ASA but this time, the ASA in place is requirement. The ASA are deployed in transparent mode. I am able to pass the LDP traffic and see the neighbor. All neighbors are reachable via routing, but cannot built the VC.

the deployment is:

6506E-------ASA5520------7206-------7206------ASA-------6506E

Has anyone tried this successfully? If yes, what are the requirement to build the L2TP tunnel through an ASA?

Thanks

1 Reply 1

Phillip Remaker
Cisco Employee
Cisco Employee

LDP runs over TCP or UDP, so the ASA will pass it.

The actual MPLS frames are ethertype 0x8847 and 0x8848, so you need to allow that in an ethertype access list in the transparent firewall.

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/acl_ethertype.html

Review Cisco Networking for a $25 gift card