08-21-2011 09:44 AM - edited 03-04-2019 01:20 PM
Hello, we have remote sites using 1841 routers coming back to a 2821 router at headquarters across the WAN. We also have an ASA 5510 at headquarters. What would be the best way to configure an encrypted WAN? Would additional equipment be needed?
Sent from Cisco Technical Support iPad App
08-21-2011 10:17 AM
Hello,
with the current hardware you can have supported IPsec over your WAN links, you just need to make sure you have the correct IOS Software feature set on the 1841 that supports IPsec.
If its, then you can terminate many LAN-to-LAN IPsec tunnels between your ASA and 1841 Spokes.
Regards,
Mohamed
08-22-2011 08:25 AM
Thanks for the info Mohamed. From what I read the 1841's basic specifications have Onboard VPN encryption acceleration-IP Security (IPSec). I did a sh vers on one of the 1841's and this is what I have:
ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
System image file is "flash:c1841-advipservicesk9-mz.124-15.T7.bin"
Does that look like the correct IOS software?
08-22-2011 10:43 AM
Hi Dave,
Yes that IOS is the correct one and it should support IPsec.
Regards,
Mohamed
08-22-2011 01:52 PM
Thanks Mohamed
08-22-2011 08:51 AM
How many remote sites do you have? There may be better options for you like DMVPN or possibly GETVPN.
08-22-2011 09:55 AM
I have 17 remotes sites now. They all have 1841's which come back across the WAN to a 2821 at headquarters. We also have our routers doing failover with our DR site so if I change the WAN I may need another failover option.
08-22-2011 11:46 AM
With that many remote sites definitely look into DMVPN and GETVPN. GETVPN is not supported by the ASA so you would need to use another router at the head end.
DMVPN
http://www.cisco.com/en/US/products/ps6658/index.html
GETVPN
08-22-2011 01:52 PM
Thanks Collin, I will take a look at that.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide