cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
378
Views
0
Helpful
1
Replies

Site-to-Site VPN over PPoE Internet Using ASA

david.walsh
Level 1
Level 1

Hello,

I have a client that wants to establisha S2S VPN across the Internet.  His Canada site (using an ASA5510) has a traditional fibre Internet service. However, the Chilean side (using an ASA5505) is using a PPoE Internet service.  The Chilean IP is dedicated, but the host IP they've received is the same as the default gateway (odd).

Anyway, given that it's a PPoE Internet connection with authentication required, is it even possible to establish a S2S VPN.  I guess I'm thinking that if the Canada side tries to initiate to the Chilean side without anyone on their end to initiate the traffic first (and therefore authenticate in the process), will this even work?

Any thoughts are welcome.

Thanks,

Dave

1 Reply 1

Hi,

You can establish a Site-to-Site VPN connection between the two sites and it doesn't matter which Internet connection type they have (as long as there is IP reachability between both sides and IPsec is not blocked).

Now, when one side of the VPN connection has a dynamic IP, then you have some options for example:

Static-to-dynamic Site-to-Site VPN

EzVPN

Either way, the tunnel should be initiated from the dynamic side, but they work with no problems.

Hope it helps.


Federico.