cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
398
Views
0
Helpful
1
Replies

EOMPLS via ASA

tshibos
Level 1
Level 1

I am trying to build an EoMPLS connection between 2 sites via 2 ASA on each site. The goal to is to extend 1 or more VLAN between sites. It has been deployed successfully in the past without ASA but this time, the ASA in place is requirement. The ASA are deployed in transparent mode. I am able to pass the LDP traffic and see the neighbor. All neighbors are reachable via routing, but cannot built the VC.

the deployment is:

6506E-------ASA5520------7206-------7206------ASA-------6506E

Has anyone tried this successfully? If yes, what are the requirement to build the L2TP tunnel through an ASA?

Thanks

1 Reply 1

Phillip Remaker
Cisco Employee
Cisco Employee

LDP runs over TCP or UDP, so the ASA will pass it.

The actual MPLS frames are ethertype 0x8847 and 0x8848, so you need to allow that in an ethertype access list in the transparent firewall.

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/acl_ethertype.html

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: