cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
936
Views
0
Helpful
2
Replies

Count Subnets on Cisco ASA IPsec

MindVersal
Level 1
Level 1

Hello!

 

Interesting, how mach can I add subnets to the IPsec tunnel on Cisco ASA?

Now, when I add to the tunnel, some subnets are not visible in the tunnel,

but after the rebuild, others not are visible...

 

Configuration:

Cisco ASA 5515-X (~30 subnets) <= IPsec (ikev1) => Cisco ASA 5520 (~20 subnets)

 

What do you think about this interesting situation?

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

The IKEv1 SA will establish when any interesting traffic is presented to a tunnel endpoint.

 

The IPsec SAs (which the subnets are included in) form dynamically when pairwise traffic flows. So some might remain inactive if there's no communications between those particular subnets.

Yes, when traffic appears, subnets appears in tunnel,
but the problem is that connectivity is not established between some pairs of subnets.
(I have a ping between subnets, and sometimes there are pairs of subnets in the tunnel,
but sometimes they are not)

Now tunnel ID is 45 for one IPsec tunnel, but under load increases to 170.
(This is count pairs subnets in IPsec tunnel)

Is it possible, what a non-stable operation of a tunnel is due to the fact that there are many subnets in IPsec?
And where to find the number of subnets that can be added to a single tunnel?

Thanks for answers!