cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
380
Views
0
Helpful
3
Replies

site to site vpn ASR 1K to ASA FW

Jaakov Ettdgi
Level 1
Level 1

Hi,

I am  trying to implement a site to site vpn between ASR 1K and ASA FW. 

On the ASR I am using tunnel mode ipsec ipv4 with Tunnel protection and on the ASA I am using crypto-map. 

Is it a valid configuration ?

Thanks,

Koby,

3 Replies 3

Philip D'Ath
VIP Alumni
VIP Alumni

I have found that combination to be very problematic.

Change to using a crypto map on the ASR and life will be simple.

Thanks,

this is cisco TAC engineer answer:

You would like to also know if the tunnel interface with tunnel protection will work with crypto map on ASA.

The answer is that you need to use either:

So if the tunnel will be negotiated only from ASA side I recommend to use dVTI, but if you need negotiate the tunnel from both sides you have to use crypto map on the ASR as well. If you choose sVTI the problem will be during the rekey, because a sVTI always uses 0.0.0.0 to 0.0.0.0 as proxy-identity set and the ASA will not like it.

 

 

I would probably phrase it by saying crypto maps are "mature technology" rather than saying "legacy".  And because you are trying to talk to an ASA that does not support dVTI you are more likely to have issues interfacing two different technologies.

If you use a crypto map then you are using the same technology at both ends.  Much less grief.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: