Route VPN site to site on a route other than the default gateway

Answered Question
Mar 22nd, 2010
User Badges:

I would like to route VPN site to site on a route other than the default gateway


Asa 5510

os 8.0 soon 8.3


1 interface line adsl  (surf) default gateway

1 interface line SDSL (10 VPN site to site)


1 interface LAN


that it is possible ?

thank you


Sorry for my English

Attachment: 
Correct Answer by Jennifer Halim about 7 years 6 days ago

Here is the assumption that I will make:

- Your SHDL interface ip address is 200.1.1.1, and next hop is 200.1.1.2

- Your LAN-to-LAN is terminated on this interface (crypto map interface SHDL)

- VPN peer 1 - 150.1.1.1, and LAN is 192.168.1.0/24

- VPN peer 2 - 175.1.1.1, and LAN is 192.168.5.0/24


Here is the routing based on the above assumption:

route SHDL 150.1.1.1 255.255.255.255 200.1.1.2

route SHDL 175.1.1.1 255.255.255.255 200.1.1.2

route SHDL 192.168.1.0 255.255.255.0 200.1.1.2

route SHDL 192.168.5.0 255.255.255.0 200.1.1.2


Hope that helps.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Jennifer Halim Mon, 03/22/2010 - 03:20
User Badges:
  • Cisco Employee,

Yes that is possible for the site-to-site vpn tunnel.


The VPN must terminate on the SDSL line interface of the ASA, and you would need to configure the following route pointing towards the SDSL line next hop:

- Route for the crypto peer addresses

- Route for the peer LAN subnets


Hope that helps.

asstec2 Mon, 03/22/2010 - 04:17
User Badges:

Thank you for your response

Could you give me an example for different routing?

Correct Answer
Jennifer Halim Mon, 03/22/2010 - 04:33
User Badges:
  • Cisco Employee,

Here is the assumption that I will make:

- Your SHDL interface ip address is 200.1.1.1, and next hop is 200.1.1.2

- Your LAN-to-LAN is terminated on this interface (crypto map interface SHDL)

- VPN peer 1 - 150.1.1.1, and LAN is 192.168.1.0/24

- VPN peer 2 - 175.1.1.1, and LAN is 192.168.5.0/24


Here is the routing based on the above assumption:

route SHDL 150.1.1.1 255.255.255.255 200.1.1.2

route SHDL 175.1.1.1 255.255.255.255 200.1.1.2

route SHDL 192.168.1.0 255.255.255.0 200.1.1.2

route SHDL 192.168.5.0 255.255.255.0 200.1.1.2


Hope that helps.

Actions

This Discussion