Backup VPN, IOS to ASA

Unanswered Question
Nov 27th, 2007
User Badges:

We have an ASA 7.x at the central location acting as a firewall and VPN concentrator. We also have a remote site connected internally through Frame Relay to a router that's behind the ASA. We're running EIGRP internally. We've added an internet connection to the remote site router and would like to use it for backup purposes in the event the WAN link fails.


I've been looking into a number of options but nothing looks like it'll work quite right. Is there a way to kick off the VPN tunnel from the remote side when it senses a WAN link failure? The VPN can't be up when the WAN link is up.


EasyVPN doesn't seem to have a way to fail over from a non-VPN connection.


DMVPN doesn't seem to be supported on the ASA.


Anyone have a guide they can point me at to get this working?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
dominic.caron Wed, 11/28/2007 - 06:22
User Badges:
  • Silver, 250 points or more

In a case like this, your primary need is routing feature, not vpn. What you need on both side is a router with encryption capacity and not a ASA.


I see one way of doing this easily, on your WAN routers, configure a GRE tunnel. (you'll need to fine tune your routing protocol to use the FR link)


Review this link. I have a similar config using OSPF and It works fine.


http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a008009438e.shtml



Please rate helpful post

Actions

This Discussion