01-23-2015 06:04 AM
Can i enable VPN (anyconnect) access on 2 separate interfaces ? using the same anyconnect profile and address pool?
I have my outside vpn access working fine, but now would like the users on a guest interface to be able to "VPN" into my prod network if needed. can i simply just enable vpn access on that interface(guest)?
thanks
02-18-2015 06:16 PM
Yes, you should be able to enable vpn on the Outside and the Guest Interface and use the same profles. However, it is a good idea to have separate profiles and address pools so that you can better control where guests go.
Thanks
John
02-20-2015 10:39 AM
I have configured VPN on two interfaces of an ASA and it works fine. John does make an interesting point that from a policy perspective that you might want to treat traffic differently if it comes from a guest interface. But in terms of the original question, yes it works to enable VPN on two interfaces of the same ASA.
HTH
Rick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide