cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
615
Views
0
Helpful
3
Replies

ASA Site to Site IPSec IKev2 can I use alternate tunnel source IP Addr

I had a request to set up a VPN ikev2 tunnel and was setting up a vti tunnel interface and all was going well except... 

The request was to have it originate from an IP address on our outside interface that is not the default IP address.

Easy to do with NAT, but I cannot find any hooks on which to hang a tunnel source address, only the source interface. 

Am I missing the obvious, or do tunnel interfaces always have to source from the single default source interface address? 

Thanks, Linwood

1 Accepted Solution

Accepted Solutions

cco@leferguson.com you can only source a VPN tunnel from the physical interface IP address.

 

You also can only terminate a VPN tunnel on the ASA physical interface IP address.

View solution in original post

3 Replies 3

cco@leferguson.com you can only source a VPN tunnel from the physical interface IP address.

 

You also can only terminate a VPN tunnel on the ASA physical interface IP address.

Well, shoot.  Thanks for the quick confirmation.

Unfortunately you need to use interface as tunnel source, you can't use ip even if it reachable.