cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1137
Views
0
Helpful
1
Replies

ASA 5520 as VPN Concentrator behind Meraki MX

plee55
Level 1
Level 1

All:

I am in the pre-lim portion of the configs/design for a VPN solution.  Just seeing if anyone has tried this before, and the success rate:

using an ASA 5520 as VPN Concentrator, behind a Meraki MX appliance?  the Concentrator will be used for Anyconnect clients and other remote sites using other ASA appliances for connectivity.

(The reason for this type of config is b/c the Meraki's VPN solution is not as good and is not compatible with Anyconnect.)

thanks

Paul

1 Reply 1

cmckeown72
Level 1
Level 1

Not sure if you received your answer or not? Thought I'd respond anyway for posterity.

 

It's definitely possible to deploy the ASA in a one-armed configuration with the MX appliance. We run several vpn head ends using this design. AnyConnect clients authenticate using Radius, and setting up the port forwarding rules was pretty basic.. We run two ISP's at each site for redundancy, so I typically route VPN traffic through the secondary WAN port to help offload AnyConnect user traffic from the primary internet service.