cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
406
Views
0
Helpful
1
Replies

Backup VPN, IOS to ASA

sbrooke
Level 1
Level 1

We have an ASA 7.x at the central location acting as a firewall and VPN concentrator. We also have a remote site connected internally through Frame Relay to a router that's behind the ASA. We're running EIGRP internally. We've added an internet connection to the remote site router and would like to use it for backup purposes in the event the WAN link fails.

I've been looking into a number of options but nothing looks like it'll work quite right. Is there a way to kick off the VPN tunnel from the remote side when it senses a WAN link failure? The VPN can't be up when the WAN link is up.

EasyVPN doesn't seem to have a way to fail over from a non-VPN connection.

DMVPN doesn't seem to be supported on the ASA.

Anyone have a guide they can point me at to get this working?

1 Reply 1

dominic.caron
Level 5
Level 5

In a case like this, your primary need is routing feature, not vpn. What you need on both side is a router with encryption capacity and not a ASA.

I see one way of doing this easily, on your WAN routers, configure a GRE tunnel. (you'll need to fine tune your routing protocol to use the FR link)

Review this link. I have a similar config using OSPF and It works fine.

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a008009438e.shtml

Please rate helpful post

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: