02-06-2016 12:59 PM
Hello! I was wondering if I can get some opinions on doing a network as a Full Mesh or Hub and Spoke design. I have about 20 sites all over with primarily Cisco ASA firewalls anywhere from 5505, 5506, 5510, 5520, 5515 and they all have site-to-site VPN tunnels.
I really like the idea of a full mesh design, creates some redundancy and allows the locations to get to each other without having to go through a central Hub. However, maintaining all the tunnels is not the easiest thing in the world and can be time consuming.
Was curious what other folks thought and if they've run in to the same issues trying to do a Full Mesh design.
02-06-2016 10:39 PM
If you were using Cisco IOS routers then you could use DMVPN, and this would be trivial ...
In an ASA environment like this it is not practical to do a full mesh. The configs would be huge and unmanageable.
02-09-2016 07:50 PM
Yea that's the challenge I'm having, managing all the tunnels is a bit inconvenient.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide