cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1006
Views
0
Helpful
4
Replies

ASA IKEv1 L2L Tunnel and cisco anyconnect ikev2 vpn dial-in working on the same outside interface

Hi,

 

currently we use ikev1 dial-in with Mac Cisco IPsec client in parallel on the same interface. Because of future win10 client we had/we plan to use Cisco Anyconnect client with ikev2 and certificate. Does this work with the L2L ikev1 tunnel or do we have to change this too? I've red in this forum, that Cisco IPsec client (Mac) and win10 Cisco AnyConnect client doesn't work in together / in parallel on the same outside interface? Is there any experience with this constellation in this forum.

Many thx in advance

 

Steve

 

2 Accepted Solutions

Accepted Solutions

Hi s.schuler@sys-tec.info 

Yes, RAVPN = Remote Access VPN

 

Yes, you can have L2L IKEv1 and IKEv2 AnyConnect RAVPN on the same interface.

 

HTH

View solution in original post

4 Replies 4

Hi s.schuler@sys-tec.info 

Yes, you can have an IKEv1 L2L VPN and IKEv2 RAVPN enabled on the outside interface.

When you say Cisco IPSec client are you referring to the old Cisco VPN client (pre anyconnect)?....this would no longer be supported. You get the most performance/security by running anyconnect.

 

HTH

Hi Rob,

 

first of all many thx. I'm a little bit confused. Yes we are using the Cisco IPSec Client build in in the MacOS, which is the same as the pre-Anyconnect Client (now VPN Client, cisco changed the naming ome weeks before).

I know that the mentioned old Cisco IPSEC client will not be supported by Cisco amymore

So to be exactly, what do you mean with RAVPN (remote Access?).

 

Our future scenario will be (one the same ASA outside interface, using 'classical ASA firmware, not FTD)

L2L tunnels to subsidiaries via IKEv1 with pre-shared keys

and

Cisco Anyconnect Client, IKEv2 with certificate and xml-profiles on the clients

 Will this work?

 

Many thanks in advanced

 

Steve

 

Hi s.schuler@sys-tec.info 

Yes, RAVPN = Remote Access VPN

 

Yes, you can have L2L IKEv1 and IKEv2 AnyConnect RAVPN on the same interface.

 

HTH

many thx

Steve