04-07-2016 05:11 PM - edited 03-05-2019 03:44 AM
Hi,
i have 2 internet circuits primarily for Remote access VPN, S2S and internet traffic, in other hand 2 circuits for DMVPN traffic for remote locations to reach data center for accessing internal resources and web traffic, i want to setup RA and S2S in Cisco ASA 5585. can anyone suggest how can i setup this links in best way.
Regards,
Sankar
04-07-2016 05:47 PM
Can you use the same netblock on each of the two circuits (aka you can do BGP and the like for failover), are do they use provider dependent IP addressing (aka, each circuit has a different netblock)?
04-07-2016 05:58 PM
i think it will be different net-block only, we are still in progress of procurement phase on links..
04-07-2016 06:02 PM
We you be able to use a router to terminate the two links, rather than terminating both links on the firewall (highly recommended - make that strongly recommended)?
04-07-2016 06:06 PM
Even my intention is to terminate in Routing device rather firewall, also how about creating VDCs for each links on nexus switch ?
04-07-2016 06:08 PM
I'm not really keen on using Nexus switches to be honest. As soon as you start using routing and Portchannels life gets a million times more complicated.
Are you able to use standalone edge router to do the job?
04-07-2016 06:14 PM
Sure, but remember we have 4 links altogether, am not network specialist but am security guy and i want to achieve my cisco ASA configs without any issues.
04-07-2016 06:25 PM
What sort of speed are the links going to be?
04-07-2016 06:27 PM
200Mbps, 500Mbps Internet, other links yet to be determined.. any suggesion for this design?
04-07-2016 06:56 PM
You might be better of telling the provider you want a redundant pair of Internet links, presented to you so you can plug a pair of ASA's into, where the outside interfaces are in the same VLAN, and where they provide first hop )aka default gateway) protection.
Then you only have to worry about the ASA part.
With regard to DMVPN, that part is simple since it is so flexible.
04-07-2016 07:01 PM
this is fine, but not sure how the link procurement going to be done. thanks much.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide