cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
434
Views
3
Helpful
5
Replies

Two VPN tunnels, same ASA, different end points, same Enc Domain?

jamesholley
Level 1
Level 1

Hi all

I am experienced with Cisco ASA and VPN, but have come across a design that I have not configured before.

We have a pair of ASAv firewalls in an Azure environment and need to build two redundant tunnels to non-Cisco VPN peers.

Thus we will have two peers, the same encryption domain, and the traffic will leave the same outside interface.

I have configured it to share the same crypto map, so is it as simple as the ASAv will simply try the second tunnel if the first one stops responding to DPD's, or do I need to set up some kind of IP SLA to swing from one VPN tunnel to the other.

Thanks in advance!

 

 

James

 

2 Accepted Solutions

Accepted Solutions

mkazam001
Level 3
Level 3

That's correct, if the first peer fails the IPSec tunnel will be established to the second peer automatically.

This worked on IKEv1 but only from Version 9.14 on IKEv2, so as long as you have this or higher.

regards

kazam

View solution in original post

Set peer x.x.x.x y.y.y.y

Here if ASAv can not connect to x.x.x.x it will connect to y.y.y.y

View solution in original post

5 Replies 5

mkazam001
Level 3
Level 3

Hi James,

If its a policy-based VPN, you can configure x2 tunnel-groups, 1 for each peer & set multiple peers within the same crypto map.

If its a route-based VPN, redundancy can be configured using BGP.

regards

kazam

Thanks Kazam, yes it is a policy based VPN. And the failover from one to the other if peer connectivity fails is automatic?

 

mkazam001
Level 3
Level 3

That's correct, if the first peer fails the IPSec tunnel will be established to the second peer automatically.

This worked on IKEv1 but only from Version 9.14 on IKEv2, so as long as you have this or higher.

regards

kazam

Set peer x.x.x.x y.y.y.y

Here if ASAv can not connect to x.x.x.x it will connect to y.y.y.y

Thanks, of course, that works a treat!