cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1082
Views
0
Helpful
3
Replies

dual ISP and SSL VPN on ASA 5520

peterpark421
Level 1
Level 1

Hi All,

I configured dual ISP on ASA 5520 with a help of cisco doc below. Now I would like to configure SSL VPN to work with this for failover? Could anyone shed some light on me for this one? I tried to find an article regarding this but I could not.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

3 Replies 3

Jitendra Siyag
Level 1
Level 1

you can configure the SSLVPN same way as in one ISP case. and after that enable webvpn on backup intreface also using below command.

webvpn

    enable backup

that way when priamry ISP goes down the users can connect via secondary ISP.

here is a deployment guide for SSLVPN.

http://www.cisco.com/en/US/docs/security/asa/asa80/asdm60/ssl_vpn_deployment_guide/deploy.html#wp1128724

Thank you, Jitendra.

I will try this and will update here.

One thing to keep in mind is that once the failover occurs the internet-facing IP address of your ASA will change, which will mean the old URL may not work anymore (depending on your topology; I'm assuming your ASA has public addresses on Internet-facing links).  Just be sure to either use a service that will update your DNS records if the first link goes down or make sure users are trained to use a new URL in the event of an outage.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: