cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1145
Views
0
Helpful
9
Replies

SSL VPN issue on cisco firewall

Nitin S
Level 5
Level 5

Hello All,

 

We have three Cisco 5545 ASA firewall configure for SSL VPN & this three firewall are in VPN load balancer. for inside & Outside we have separate switch . also we have one vrf interconnect to VPN firewall(different switch for vrf).

recently we faced issue inside/customer vrf switch was down but  same time outside UP & internet was reachable from firewall & due to that users where able to connect vpn but nothing was accessible from them.


is there any way to have configuration  if firewall inside/vrf interface/switch goes down than this firewall should not take any vpn load/new session. or any other possibility. 

looking forward for support.

9 Replies 9

Hi @Nitin S 

Run an EEM script in conjunction with IP SLA on each ASA to determine whether the next hop/interface is down, in the event of failure disable crypto on the outside interface.

 

HTH

Nitin S
Level 5
Level 5

Hi Rob

Thanks for reply. can you please help with some sample config.

I don't have access to my lab for a few days, but refer to this link

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118087-technote-asa-00.html

 

...have a look at the VPN preempt example, use that as an example, change the eem action to disable webvpn as below:-

 

webvpn
no enable OUTSIDE

You will need to test in a lab to tweak as appropriate.

 

HTH

Nitin S
Level 5
Level 5

i try in LAB but i can't call track on interface 

Use ICMP track for the IP address of the next hop device that is connected to that interface.

Nitin S
Level 5
Level 5

sla monitor 100
type echo protocol ipIcmpEcho 10.2.2.1 interface lan
num-packets 3
frequency 10

sla monitor schedule 100 life forever start-time now

track 1 rtr 100 reachability


event manager applet PREEMPT
event syslog id 622001 occurs 2
action 1 cli command "wevpn"
action 2 cli command "no enable wan"
output none

interface gig0/1
nameif lan
security-level 0
ip address 10.2.2.2 255.255.252

next hop 10.2.2.1

You'll need another EEM script to re-enable when the IP SLA is active again.

when i shutdown port LAN event is not trigger what will process to trigger event. 

 

ASAipsla3.PNG

You need to determine what syslog message is logged and amend your applet accordingly