cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
729
Views
0
Helpful
6
Replies

ASA backup server command

yussetamayo
Level 1
Level 1

I know you can define a backup server when you are configuring a remote client on the asa and the client download the backup server's ips. the question is if you can define the same when you are configuring a site-to-site vpn????

6 Replies 6

andrew.prince
Level 10
Level 10

Yusset,

AFAIK - you cannot use this feature for l2l connections.

HTH.

Umm so the only way i can do something like that is using L2 tunnel with dinamyc ip address??

In my opinion if you want a failover network with VPN's the ideal way would be with a dynamic routing protocol over GRE tunnels in the VPN's. This is was I have with +100 VPN tunnels, using EIGRP, GRE tunnels and VPN's.

HTH.

a.alekseev
Level 7
Level 7

Yes, you can but with some restritions.

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c5.html#wp2152979

crypto map mymap 10 set peer 10.0.0.1 10.0.0.2

The idea is, two coming vpn from internet, ending in two diferent asa, if one of them goes down i want to set up a vpn in the other asa automatically

with such redundancy, I mean

"crypto map mymap 10 set peer 10.0.0.1 10.0.0.2"

оnly remote ASA can initiate connection.

asa1

|____________remote_asa

|

asa2

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card