cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
358
Views
0
Helpful
1
Replies

Site-to-site VPN | 2xASA5510 statefull Active/Passive-to-??? (what to buy, technical Q)

I hope this is the right community for this question.

So i have configuration like on image:

question cisco forum.jpg

I have right now on main site (site A) 2x ASA 5510, they are working in statefull Active/Passive configuration for now with software 7.2 and Security Plus license. Site A is the main site – there are few others sites connecting to site A over VPN (like site B). From SITE A all specified networks in other sites all available. From other sites only SITE A network is available. On site B for now I have old PIX501 with DSL Internet access. I want to buy second Internet access and achieve backup-access or load-balance across connections on site B.

QUESTIONS:

1.     1. Is load balance achievable with ASA5510 installed on site A? From article http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml i read that no. When not than I am assuming that on site B static route tracking feature will be used. So I will have main connection over some PRIMARY ISP gateway that will be checked if it is available and when not the default gateway from SECONDARY ISP will be used.

2.     2. What Cisco hardware should I buy to achieve on site B Internet access for clients and VPN to site A. I must tick that on site A upgrade to ASA 8.3 is planned.

3.     3. If there must be done any additional configuration for site A excluding that I must add ability to establish connection from new IP address of NEW ISP. (When there will be no second connection (to site A) in the same time I must only configure ability to establish VPN from new IP address of NEW ISP from site B). Right?

4.     4. I think that I must not even configure new route through VPN established through NEW ISP since on site A I will be using the same VPN profile like for the old connection – so internal VPN address that will site B router/asa get will be the same for both ISPs – am I right?

5.     5. Is there any manual that fits the situation presented by me?

6.     6. When my questions are dummy please give me a hint what should I read to ask wise questions

1 Reply 1

Anyone?