cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
678
Views
0
Helpful
1
Replies

Two IPSEC tunnels on same physcial interface

Roger Base
Level 1
Level 1

Hi forum.

 

I am trying to configure two separate IPSEC tunnels on the same physical interface on my ASAv 9.8 code. Will this be technically on asa ASAV ?

 

Dynamic IPSEC in one side (reasoning dynamic IP) and Static or Routed IPSEC in the other side (VTI)? My PC1 and PC2 should be able to communicate with each other over the tunnels. How should the NAT and IPSEC config look like on ASAv?

Thank you.

1 Reply 1

You can do that. What you need:

  • NAT Exemption for your whole VPN-traffic where needed
  • same-security-traffic permit intra-interface
  • ASA3 needs to route traffic for the internal ASA4-subnet and the ASA1 subnet through the tunnel
  • ASA1/ASAv need to encrypt all traffic for ASA1-ASAv-subnet and ASA1-ASA3-subnet