cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3562
Views
0
Helpful
2
Replies

Rerervse-route injection into OSPF for SSL VPN remote connections to ASA

zheka_pefti
Level 2
Level 2

Hi folks,

I'm curious if there's a way to configure RRI into an OSPF process for VPN connections done via AnyConnect (SSL VPN). I thought it could be done similar to IPSec and configure it by adding "reverse-route" statement into a crypto map but it appears it won't work that way. Any ideas ?

Thanks, Eugene

2 Replies 2

jefferyshi
Level 1
Level 1

Hi Eugene

You need ocnfigure IP pool for SSL, once remote user connect to ASA successful, it will automatically generate one host static route.

You may set OSPF policy to redistribute it to IGP. Once the user disconnect, the host static will disappear.

S    192.168.1.149 255.255.255.255 [1/0] via "internet gateway", outside

Jeffery

Hi Jeffery

Do you know if there is a way to summarize the host routes before advertising into OSPF?

Thanks,

Ernst