11-30-2012 10:51 AM - edited 02-21-2020 06:31 PM
Hi all, just looking for some input of the best way to migrate to a new pool for remote access DHCP address assignment. We are currently using a /24 pool, allowing us 253 IP Addresses... during the recent hurricane we hit 250 IP Addresses used, and had to start asking users to connect to our backup ASA VPN device in another country, not an ideal solution. I'd like to expand our current VPN subnet to a /23, however I do not have a free /24 subnet above (or below) our current /24 subnet.
I can certainly allocate a new /23 subnet, but I am looking for the best migration plan with minimal downtime (no downtime would be preferred). Can I just add the new pool range to the tunnel-group RAVPN general-attributes section alongside the current pool, or should I just remove the old pool, log off all existing remote access VPN users and have them log on again to start using the new pool?
We are running ASA Version 8.2(1).
Thanks!
Solved! Go to Solution.
11-30-2012 11:22 AM
Hi,
I would have to confirm (EDIT: checked it while writing this ) this myself as I havent had need for it previously BUT to my understanding you should be able to assing more than one DHCP pool on a single VPN Client connection.
Please check this Cisco ASA Command Reference for 8.2
VPN Pool configuration under Tunnel-group configurations
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a2.html#wp1656186
VPN Pool configuration under Group-policy configurations
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a2.html#wp1660582
They are actually the at the same spot of the same document.
Seems to me that it should be no problem to add another /24 Pool to your VPN Client configurations (and do the needed ACL / NAT Configurations)
- Jouni
11-30-2012 11:22 AM
Hi,
I would have to confirm (EDIT: checked it while writing this ) this myself as I havent had need for it previously BUT to my understanding you should be able to assing more than one DHCP pool on a single VPN Client connection.
Please check this Cisco ASA Command Reference for 8.2
VPN Pool configuration under Tunnel-group configurations
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a2.html#wp1656186
VPN Pool configuration under Group-policy configurations
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a2.html#wp1660582
They are actually the at the same spot of the same document.
Seems to me that it should be no problem to add another /24 Pool to your VPN Client configurations (and do the needed ACL / NAT Configurations)
- Jouni
11-30-2012 11:32 AM
Excellent, thanks for the reply and the info, looks like i can just add a new subnet. Great news!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide