cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2795
Views
0
Helpful
2
Replies

Can you create a site-to-site VPN without access to public IP?

dkraut
Level 1
Level 1

My first thought was no, but I realize the ASA has many tricks... Here's the scenario.  Our HQ office has an ASA 5510 with full access to internal and external IP's.  We have a small group of remote users that are working from a shared office suite and they only have Internet access by way of internal default gateway.  Using a VPN client is not desirable due to many other devices requiring access to HQ.  Is there a way to create a site-to-site VPN from this remote office space back to HQ (ASA 5510) if they have no access to the public IP address on their end?

Thanks!

2 Replies 2

mvsheik123
Level 7
Level 7

Hi,

If you are coming via internet, you need to have a public ip (static/dhcp) in order to establish s2s vpn. Not to side track your questions, but even if there is a way to to do this, your shared office user traffic will be traversing through rest of the users traffic (till the point of encryption) and this is wil be a security risk.

Thx

MS

Hi,

Both VPN endpoints must be able to reach each other.

In order words, basic connectivity is required.

Please keep us posted.

Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: