JORGE RODRIGUEZ Thu, 04/24/2008 - 20:34


You can have multiple L2L vpn tunnels within a single IPsec L2L capable device sort of a HUB and spoke. If you have a tunnel aleady stablished Between say Site-A and Site-B and you need to create another tunnel Say Site-A and Site-C yes you can. If you have a tunnel between Site-A and Site-B there is no need to add a second tunnel to the same destination since you already have one.


dmorelan Fri, 04/25/2008 - 03:45

Thanks for the reply.

What we have is an L2L tunnel between sites A and B of low bandwidth. We are upgrading the speed of the connection on new equipment and would like to run both L2L VPNs at the same time between sites A and B.

If we can't do that I need to know how to easily turn off the slower L2L VPN, test the new link and be able to go back to the existing slower link quickly if we have problems.


dave moreland

JORGE RODRIGUEZ Fri, 04/25/2008 - 07:49

It should be fairly straight forward as long there are no changes in logical configurations, I did not ask where your tunnels are terminated firewalls outside interface ? ASAs PIXes Routers?

For testing purposes for example, you could prepare/pre-configure a connection to the switches for the new link and have the port in a shutdown state, same vlan as the slow link port, pre-configure the new device caring the NEW Link with the same logical configuration as the Slow link, here you do not have to make any chnages on the L2L vpn configurations on either end as long both side applies this test principle. When the time is ready to test you can shutdown the switch port of the Slow link and bring up the switch port connecting the new link , at this point your L2L tunnels will drop, however, you may bring up the tunnels by sending interesting traffic and proceed with IP connectivity test bewteen the two sites using new Link, if for any reason there are issues allocate a announced implementation test window of 1 hour for troubleshooting, in the event you need to fall back you can revert the switch ports shutdown and bring up you did at the begining and bring the connectivity back to the slow link.

Does this make sence ?


dmorelan Mon, 04/28/2008 - 06:45

It does make sense but let me add a little more detail...

What we have is site A with a slow link to site B. The equipment at site B (ASA 5510) is staying in place. We added a new ASA 5510 at site A and want to test a new, faster link to site B from that new device. The new ASA at site A is ready and have the second VPN config for site B ready.

What I need is a way to disable the current VPN tunnel at site B, turn on the new tunnel config at site B and test the connection to the new ASA at site A. The revert back to the slow link if I have problems.

Is this confusing or clarifying ?

dave moreland


