05-06-2011 07:13 PM
We have a Cisco ASA 5580-20 running version 8.2. We will have a consultant who will have laptops and a printer on our network but I will confine these to a VLAN. For this consultant I will need to setup a site to site VPN using our ASA to his company’s ASA. On our side I need this site to site VPN to be confined to the VLAN which his laptops and printer are assigned. Providing him with a broadband connection to use his own firewall device is not an option. I would appreciate any assistance with how to configure (restrict) the site to site to the VLAN on our side.
Thank you,
Jeff
Solved! Go to Solution.
05-06-2011 11:45 PM
Jeff,
On the Interesting traffic, You only need to allow the Consultant VLAN Subnet in the Crypto traffic (the Encrypted traffic).
Regards,
Mohameed
05-07-2011 10:42 AM
Jeff,
The link below should be of help of how to configure LAN to LAN IPsec example with NAT.
Let me know if you have any questions on it,
Regards,
Mohamed
05-06-2011 11:45 PM
Jeff,
On the Interesting traffic, You only need to allow the Consultant VLAN Subnet in the Crypto traffic (the Encrypted traffic).
Regards,
Mohameed
05-07-2011 06:06 AM
Mohameed, thank you for the reply. Not sure if it makes a difference but the consultant VLAN will be a non routed VLAN.
Jeff
05-07-2011 06:22 AM
Hi Jeff,
I am not sure I understood your point, can you just elaborate more on your current existing setup and what exactly you require?
Regards,
Mohamed
05-07-2011 06:58 AM
We would like to restrict a specific site to site VPN on the ASA to a specific VLAN on our network; which consists of Cisco switches, over two dozen VLANs and dot1q and ISL trunks. I'm new to this company and trying to get a handle on the network layout so there is not much more detail I can provide at this time. I'm looking for guidance or referrence on the ASA side of configuring a site to site VPN to a specific VLAN as this is the are which I'm a little fuzzy about.
Thanks again,
Jeff
05-07-2011 10:42 AM
Jeff,
The link below should be of help of how to configure LAN to LAN IPsec example with NAT.
Let me know if you have any questions on it,
Regards,
Mohamed
05-10-2011 04:52 AM
Thank you for the responses and if I have any questions I will post them.
Jeff
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide