cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
420
Views
0
Helpful
7
Replies
Highlighted
Enthusiast

Dynamic crypto maps - ASA5500

Hello experts,

I need to know how use crypto dynamic-map with only ikev1 in a site to site vpn with two ASA5500.

Thanks.

RJB

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
VIP Advisor

Re: Dynamic crypto maps - ASA5500

Hi,

I don't believe you can load balance over 2 crypto maps, you can with VTI. With a crypto map you can configure active/standby to define 2 peers in the crypto map and use ip sla/tracking to failover to the secondary ISP connection if the primary fails. Example here.

 

HTH

View solution in original post

7 REPLIES 7
Highlighted
VIP Advisor

Re: Dynamic crypto maps - ASA5500

Hi,

Here are a few examples:-

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119007-config-asa9x-ike-ipsec-00.html

https://www.youtube.com/watch?v=jN0XM_YO0mE

 

Or is there something in particular you need help with regarding the configuration?

Highlighted
Enthusiast

Re: Dynamic crypto maps - ASA5500

Thanks RJI,

 

Well I just created an previous post, but I dont know why was clasified as spam. I'm trying to see if dynamic crypto map solve my issue.
I have one hub with two spokes working fine since long time ago. Now I got a second ISP for one of the spoke (BR1). The hub continues with only one ISP.
After setup the second tunnel (site2site vpn) I got both tunnels up. Both tunnels pass the PHASE 1 and PHASE 2 proccess but only the old tunnel pass encapsulated and encrypted traffic, the new one does not. I discover that only one crypto map works at the time.
That is I think the dynamic crypto map may work.
But I need the IKE1 because in a near future I will replace one of the spoke with a Meraki MX.

 

RJB.

Highlighted
VIP Advisor

Re: Dynamic crypto maps - ASA5500

Hi,

I don't believe you can load balance over 2 crypto maps, you can with VTI. With a crypto map you can configure active/standby to define 2 peers in the crypto map and use ip sla/tracking to failover to the secondary ISP connection if the primary fails. Example here.

 

HTH

View solution in original post

Highlighted
Enthusiast

Re: Dynamic crypto maps - ASA5500

It really is not for load balancing. I want is a backup when at BR fails the main link.

I not sure if I had to use sla and track.

RJB

Highlighted
VIP Advisor

Re: Dynamic crypto maps - ASA5500

That's fine, then that example should help
Highlighted
Enthusiast

Re: Dynamic crypto maps - ASA5500

looks good. I will do some test... thanks.

RJB.

Highlighted
Enthusiast

Re: Dynamic crypto maps - ASA5500

Hello RJI,

I solve the issue changing the preferred peer behaviour just adding the second ip to the peer list.

!

crypto map VPN 1 match address VPN-HQ-TO-BR1

crypto map VPN 1 set peer 203.7.113.2 198.55.100.2

crypto map VPN 1 set ikev1 transform-set ESP-AES256-SHA

crypto map VPN interface outside (same interface for both)

..

..

your post was helpful, thanks..