cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1101
Views
0
Helpful
0
Replies

ASA 5520 & 5505 VPN with DHCP on Outside Interface

nmoore1978
Level 1
Level 1

I'm relatively new to configuring VPN's on ASA devices.  Up to this point I've only setup site-to-site VPN's with static IP addresses on both side.  However, I have a new challenge in front of me.

I have an active/passive ASA 5520 (8.0(4)32) cluster at the office (192.168.0.0/16 divided into multiple /24 VLANs).  I want to be able to deploy ASA 5505 (8.4(1)) devices in employees homes so they can work from home using a notebook PC and a 7940 phone behind the 5505 using a 172.17.x.x/24 address.  However, I don't want the ASA 5505 to be their home router because I don't want to troubleshoot their home networking issues.  I want the 5505 to site behind their home router and force all traffic behind the 5505 into the VPN.  I also need to have access to all of my voice VLANs at the office from the remote 5505.

Is this possible?  If so can someone point me in the right direction?

It would probably look something like this:

192.168.0.0 - ASA 5520 - xxx.yyy.78.226 - Edge Router - Internet - Home Router - 192.168.x.x - ASA 5505 - 172.17.0.0

0 Replies 0