cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
598
Views
0
Helpful
0
Replies

TACACS from Secondary ASA through VPN IPSec tunnel

Dranik
Level 1
Level 1

Hello,

I have pair of ASAs in Active/Standby HA mode. ASAs have VPN tunnel going out to the data center where ISE (TACACS) servers are. I can use TACACS for the Active unit, but it seems like Standby unit can't get to ISE at all, it just times out. Since all VPN tunnels are built on Active unit, Standby unit tries to route outgoing traffic to it's own Outside interface which goes nowhere and it never makes it to Active unit to send traffic over the VPN tunnel. 

The issue is only for outgoing connection from the Secondary unit. Incoming connections (such as SSH, HTTP) work, I added appropriate NAT statement for that.

 

Any ideas how to make it work please? 

Thanks,    

0 Replies 0