cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
225
Views
0
Helpful
1
Replies

How to configure VPN as a backup connectivity in ASA

Sandeep Pathare
Level 1
Level 1

Hi,

we have leased line between our data center to branch office as a primary source of data access. also we have separate internet links in data center and branch office. is there any way we can create a VPN between these two locations by using internet links so in case if there is any issue with leased line then the traffic can be shifted to VPN configured with the help of internet connectivity.

In Juniper we can create a static routes with different priorities for VPN also. so in case of issue with any connectivity traffic can be shifted through other route.

Regards,

Sandeep    

1 Reply 1

nspasov
Cisco Employee
Cisco Employee

Hi Sandeep, with Cisco you can use floating static routes that have different admin distance. For instance, your primary router can be learning a default route 10.0.0.0 /24 from the leased line router/provider with an admin distance of 110 (let's say it is OSPF). Your router can also be configured with a static route for 10.0.0.0/24 that points to your ASA with an admin distance of 120. That way, if the dynamically learned route goes away the router will re-route traffic to your ASA. On the ASA you can have tunnel configured that will kick in when it sees "interesting" traffic. For more info check this link/book:

http://www.ciscopress.com/articles/article.asp?p=2180209&seqNum=7

I hope this helps!

Thank you for rating helpful posts!