Hi all,
I have some doubts related to VPN in Cisco products.
In my organization, we have different zones (like internal, dmz, partner, internet, etc). The communication between zones go through a firewall (Cisco ASA 5585). Also, we have a couple of ASR routers with different VRFs, each representing one of these zones. The Partner zone is used mostly for VPN site-to-site (IPSEC) and P2P links with business partners.
Today, all VPNs for Partners are being made on ASR router. However, we have complains from some network administrators, which argument it's sometimes difficult to establish/debug VPN sessions & do VPN redundancy on ASRs with third-party devices.
So, my idea was to turn ASA firewall in multi-context mode, and create a dedicated context just for these VPNs. I'm just wondering and brainstorming what are the advantages of VPN IPSEC on Router ASR x Firewall ASA. Which one is better? What are the drawbacks of each one?
Thanks in advance.
Vinicius