09-23-2015 01:13 AM - edited 07-05-2021 03:59 AM
Hello,
I have a question, which equipment initiates the data path EoIP tunnel between a corporate controller and a guest controller located in a DMZ ?
Main Controller (Trusted Zone) <----->Firewall ASA5505<----->Guest Controller (Untrusted Zone)
Thank you in advance for your answer.
Franck.
Solved! Go to Solution.
09-30-2015 08:02 AM
I agree with Rasika. Allow either side to send the traffic.
but IIRC, the lowest MAC address, per pair, is the one that initiates the EOIP tunnel.
HTH,
Steve
09-23-2015 02:21 PM
I would open EoIP (IP protocol 97) and UDP 16666 in both directions.
HTH
Rasika
09-30-2015 07:46 AM
Hello Rasika,
That's I noticed too on the ASA5505.
Many thanks,
Franck.
09-30-2015 08:02 AM
I agree with Rasika. Allow either side to send the traffic.
but IIRC, the lowest MAC address, per pair, is the one that initiates the EOIP tunnel.
HTH,
Steve
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide