cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Cisco Community Designated VIP Class of 2020

191
Views
0
Helpful
1
Replies
Beginner

site-to-site ASA 5500

I have 3 sites which need to be connected with a site-to-site VPN tunnel and all internal networks between them should be routable.

Do i need 2 (i have single point of failure, if the "central" one dies i loose connectivity between all 3 sites) or 3 tunnels (each ASA is connected to another 2) ?

Everyone's tags (3)
1 REPLY 1
Mentor

site-to-site ASA 5500

Hi,

As you say, using one ASA and the central location would cause a single point of failure.

Having 3 L2L VPN connection would mean that the 2 locations would be able to communicate with eachother even though one failed. (Naturally might be true in the other case too if the failed device/connection wasnt the central one)

All of the environments where I work are using a separate central VPN device which handles the traffic between all the sites BUT usually those sites are all only dependant on the central site anyway and have no real need to be in contact with eachother.

In most cases the central site has redundant devices and connections though so its very rarely the case that the connections are ever totally down (in our setups that I'm referring to)

- Jouni

CreatePlease to create content
Content for Community-Ad
FusionCharts will render here