07-08-2022 09:42 AM
I had a request to set up a VPN ikev2 tunnel and was setting up a vti tunnel interface and all was going well except...
The request was to have it originate from an IP address on our outside interface that is not the default IP address.
Easy to do with NAT, but I cannot find any hooks on which to hang a tunnel source address, only the source interface.
Am I missing the obvious, or do tunnel interfaces always have to source from the single default source interface address?
Thanks, Linwood
Solved! Go to Solution.
07-08-2022 09:45 AM - edited 07-08-2022 09:46 AM
cco@leferguson.com you can only source a VPN tunnel from the physical interface IP address.
You also can only terminate a VPN tunnel on the ASA physical interface IP address.
07-08-2022 09:45 AM - edited 07-08-2022 09:46 AM
cco@leferguson.com you can only source a VPN tunnel from the physical interface IP address.
You also can only terminate a VPN tunnel on the ASA physical interface IP address.
07-08-2022 09:47 AM
Well, shoot. Thanks for the quick confirmation.
07-08-2022 09:46 AM
Unfortunately you need to use interface as tunnel source, you can't use ip even if it reachable.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide