cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
630
Views
0
Helpful
1
Replies

ipsec l2l tunnel asa question

kope
Level 1
Level 1

Experts,

I have a asa and Cisco 2811, needs to build a site-to-site ipsec tunnel between them.

Due to a requirement need to encrypt inside trafic,  i need to apply on the inside interfaces on both devices to build the tunnel.

I dont see a problem but just want to check if it would work on terminating on Inside interfaces on both ipsec peers.

1 Reply 1

Thanks for posting your question.

May I know what you mean by "terminating on Inside interfaces on both ipsec peers"?

If my understanding of your question is correct, please check the following:

You can terminate the VPN connection on the inside interfaces as long as you have something like this:

               OUT                                                  OUT

Router A --------------------------- Internet --------------------------- Router B

    |                                                                                               |

    |                                                                                               |

    |--------------------------------- Private link -------------------------------  |

          IN  <------------------> IPsec tunnel <------------------> IN

As shown above, both inside interfaces need to communicate directly, as this is traffic to the Router.

Please let me know if this answers your question.