08-28-2012 11:54 PM
Hello.
Can ASA 5510(or other products) be used as SSL VPN client for site-to-site VPN?
Version 8.4.2, asdm 6.4.9
On other end have authentication by certificate and authorization by LDAP credentials
Solved! Go to Solution.
08-28-2012 11:58 PM
No, SSL on the ASA is only for Remote-Access. For Site-to-Site you have to use IPSec.
08-30-2012 12:48 AM
There are parameters in a group-policy that also belong to site-to-site VPNs (vpn-filter for example). But that can't change the transport to SSL.
How did you think may be it will in new IOS version?
perhaps, perhaps not ... I don't know it that is on the roadmap.
I wouldn't wait for it. IPSec is well known and rock solid for site-2-site. So just go for that.
If you was asking for this kind of setup because one of your devices only has a dynamic IP, that will also work with IPSec.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
08-28-2012 11:58 PM
No, SSL on the ASA is only for Remote-Access. For Site-to-Site you have to use IPSec.
08-29-2012 11:59 PM
How did you think may be it will in new IOS version?
Because I can use SSL VPN tunneling policy for site-to-site or it's won't work?
How about other products?
08-30-2012 12:48 AM
There are parameters in a group-policy that also belong to site-to-site VPNs (vpn-filter for example). But that can't change the transport to SSL.
How did you think may be it will in new IOS version?
perhaps, perhaps not ... I don't know it that is on the roadmap.
I wouldn't wait for it. IPSec is well known and rock solid for site-2-site. So just go for that.
If you was asking for this kind of setup because one of your devices only has a dynamic IP, that will also work with IPSec.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide