easy vpn or site-to-site vpn for back up connection?

Unanswered Question

Hi,

All of my remote sites are connected to HQ via MPLS circuits. I would like to create back link for those remote sites using 871 routers with DSL connection and terminate ipsec vpn tunnels at the outside interface of ASA5540 located at HQ.

The 871 routers will be configured HSRP standby mode. It becomes active and forward traffic when the main router of the remote site losses connection to HQ.

Questions:

1. Has anyone had similar requirements and use easy vpn as a solution? will site-to-site work better for this scenario?

2. How to make ASA5540 handle the routes properly when it sees the same subnets located on both Inside interface and the other end of the tunnel which is terminated at the outside interface?

Static routes are configured on the ASA.

3. I also try to avoid user entering username and password for interactive authentication in easy vpn.

Thanks so much in advance.

PH

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
ivillegas Fri, 06/15/2007 - 10:47

yes you can site-to-site VPN as a backup.

If the interface going to the backup connection is an interface different than the outside interface, and if the regular connection going down means that the outside interface will go down, then you only need an additional default route, but with a higher metric than your regular route.

But if both connections go out the same interface, or if the outside interface will not go down when the primary Internet connection goes down, then you'll need to take a different approach. ASA 7.2 code introduced a feature called "Standby ISP Support", which allows the firewall to keep an active track on an Internet connection, and if that connection

fails, switch to a different connection.

Try this link:

http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a00806403ec.html#wp1090243

Actions

This Discussion