cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3736
Views
0
Helpful
6
Replies

ASA to ASA IPSec in transport mode.

amitbatra
Level 1
Level 1

hi guys,

i have 2 ASA connected via IPSec tunnel wanna configure IPSec for 2 LAN. at the LAN we have public IP's . which means i need to configure transport mode VPN. can anyone send me a link or the basic config.

regards

6 Replies 6

vkapoor5
Level 5
Level 5

Even though the router is configured for transport mode, the router will request transport mode from its peer however it will still accept either transport or tunnel mode. Take a look at

http://www.cisco.com/en/US/docs/ios/12_0/security/command/reference/sripsec.html#wp1032317

Hi vkapoor,

Done that.  The tunnel stays up for 37 seconds, with routing information passing, then T5 on the remote 1921 changes state to down again.

thanks.

Not applicable

Hello,

By having two public IP's doesn't mean that should build your VPN tunnel using ESP+transport mode, this is only recommended when using GRE over IPSec or DMVPN to save overhead, 20 bytes.

My suggestion is to build the legacy L2L, with tunnel mode, you can see this link as a guide:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a87f7.shtml

Regards,

Enrique Quant

Not applicable

Not applicable

Not applicable

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: