813
Views
0
Helpful
1
Replies
Two IPSEC tunnels on same physcial interface
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2017 10:59 AM - edited 03-12-2019 04:46 AM
Hi forum.
I am trying to configure two separate IPSEC tunnels on the same physical interface on my ASAv 9.8 code. Will this be technically on asa ASAV ?
Dynamic IPSEC in one side (reasoning dynamic IP) and Static or Routed IPSEC in the other side (VTI)? My PC1 and PC2 should be able to communicate with each other over the tunnels. How should the NAT and IPSEC config look like on ASAv?
Thank you.
Labels:
- Labels:
-
Other VPN Topics
1 Reply 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2017 07:01 AM
You can do that. What you need:
- NAT Exemption for your whole VPN-traffic where needed
- same-security-traffic permit intra-interface
- ASA3 needs to route traffic for the internal ASA4-subnet and the ASA1 subnet through the tunnel
- ASA1/ASAv need to encrypt all traffic for ASA1-ASAv-subnet and ASA1-ASA3-subnet
