You need an affordable solution to connect multiple locations with dynamic IPs to a central VPN server.
FlexVPN/DMVPN would solve this but central IOS routers cost plenty of money and offer only a limited HA solution. You would need a HSEC license if you want to go for over 85Mbit and 225 tunnels. Also firewall management via CLI is a mess.
If you have dynamic IPs (e.g. with 4G) and don't want to go for certificates, you have to use PSK. The downside is that every PSK has to be the same via DefaultL2LGroup. To avoid this, we create IKEv2 tunnel groups and set the isakmp ID on the clients to the name of the tunnel group.
The ASA (esp. 5515-X) is quite affordable, handling multiple tunnels with high throughput. Also it offers really good HA with Active/Standby failover including stateful IPSEC failover. On the downside it doesn't support FlexVPN, so the config part on the routers is quite big.
On the client side we use 880 Branch Routers which support all needed features.
On the ASA we configure the following (only crypto parts)
Specify the subnets:
access-list outside_cryptomap extended permit ip object OUR-NET object CLIENT-NET
Hi all , has anyone came across any cisco documentation on banner grabbing prevention ?example below from running zenmap with this command nmap -sV --script banner 10.0.0.59(truncated)5060/tcp open sip Tandberg-4137 VoIP server X12.5.15061/tcp ...
Hi guys,We don't want to use NSP or certificate during the single SSID BYOD On-boarding, we just want to let user register their device's MAC address and then authorization the VLAN based on user group.I found below discussion, but seems the screen copy i...
Today I had 6 endpoints within 3 hours all quarantine the following file: 8d4fdcb52b32afbcef4450ca88668def9b245a6f7ab2aa26ec3a4324a0b1f461When I look what was happening with each endpoint in AMP's Device Trajectory I see this:The event only indicate...
After a "TelePresence SX20" disconnect occurred in a video conference, troubleshooting was initiated to identify the root cause. After log analysis, we found that the call was disconnected by H.323 timeout.I would like to know if you have any analysis or ...
I have an Ironport C670, where all licenses have expired except for Incoming Mail Handling, but the emails were "being sent" because there was no queue at the checkout, but the recipients did not receive them, however all employees were receiving and emai...