cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
345
Views
10
Helpful
4
Replies

Lan to lan tunnel and ezvpn on ASA

John Blakley
VIP Alumni
VIP Alumni

All,

I have a need to configure ezvpn remote on an asa to our office, but they also need to have a lan-to-lan tunnel to another office. Is this possible? I can't apply ezvpn if I have any isakmp policies, tunnel-groups etc, enabled on the asa.

Thanks,

John

HTH, John *** Please rate all useful posts ***
4 Replies 4

andrew.prince
Level 10
Level 10

John,

My understanding is the ezvpn is just a l2l VPN without an IP address (Dynamic L2L VPN), so you can have this running on an ASA with static l2l VPN configs.

HTH>

Hi,

ASA cannot act as L2L vpn peer and ezvpn client at the sametime. It can be ezvpn server (to accept ezvpn clients) and L2L vpn peer at the same time. [I tried this before (when we first started deploying ezvpn solution for few of our clients)].

Here is info from cisco doc:

"When used as an Easy VPN hardware client, the ASA 5505 can also be configured to perform basic firewall services, such as protecting devices in a DMZ from from unauthorized access. However, if the ASA 5505 is configured to function as an Easy VPN hardware client, it cannot establish other types of tunnels. For example, the ASA 5505 cannot function simultaneously as an Easy VPN hardware client and as one end of a standard peer-to-peer VPN deployment".

Link:

http://www.cisco.com/en/US/docs/security/asa/asa72/getting_started/asa5505/quick/guide/remcli.html

hth

MS

**Rate helpful postings**

I ended up going with a L2L tunnel for the device since I needed to terminate to two different locations. It works as intended.

Thanks,

John

HTH, John *** Please rate all useful posts ***

Great link Mehboob.

very helpful.. and I just wish that people asking questions and get good and fast answers would be more appreciative...

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: