03-21-2011 08:59 AM
I have:
ASA 8.3
ASDM 6.3
When creating a connection L2L we have the option of using a CONNECTION NAME or choosing to use the IP address. When a connection name is used their are problems establishing the L2L session- if the IP address is used for the connection name the L2L works.
Here are the two fields defintion as per ASA Help:
Has anyone else experienced this problem ???
03-21-2011 10:00 AM
connection name and IP need to be the same. Use the IP since the name is not allowed on the connection name when creating a L2L.
03-21-2011 10:01 AM
you can use a name when configuring remote access VPN.
03-21-2011 12:26 PM
Thanks Paul,
I understand what your saying - you are agreeing with me that on a L2L the connection name has to be the IP address. Now that we have agreed. On the L2L we have two fields:
1. Peer IP adress
2. Connection Name
Are we saying that the option for NOT using the IP address as the connection name does not exist. Should I open a case with Cisco ? Is there a bug with version ASA 8.3 that needs fixing ??
Clearly the setup is giving me the option to use a NAME or an IP address.
Regards,
Sergio
03-21-2011 12:44 PM
when creating a L2L tunnel the tunnel name has to be the IP address of the peer. That is the only option that works. I think that is also included on the documentation.
You can only use names when doing remote access VPN.
I will look for that documentation.
03-21-2011 01:27 PM
check this link:
Connection Name—Specifies the name assigned to this connection profile. For the Edit function, this field is display-only. You can specify that the connection name is the same as the IP address specified in the Peer IP Address field.
03-29-2011 07:36 AM
Hi Paul,
Sorry for not getting back to you sooner...
I finally got a chance to open a TAC with Cisco and the explanation given was that the CONNECTION NAME is used when the remote site is using DYNAMIC IP as its PEER address.
Here is the config I was recommended to look at.
VPN Between Sonicwall Products and Cisco Security Appliance Configuration Example
PIX/ASA 7.x and later : Dynamic IPsec Between a Statically addressed PIX and a Dynamically addressed IOS Router with NAT Configuration Example
I think we can close this discussion... thanks again for your help.
Serigo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide