Equivalent of Set Peer on ASA's - Alternate site L2L tunnel

Answered Question

     Hi,


On the ISR's you can specify more than one peer (set peer) for an IPSEC tunnel and in the event the one peer (default) goes down the second one will be tried.


I was just wondering if the same thing is possible on an ASA? I would like a branch ASA to try the primary site and in the event the primary site is unavailable try to establish a tunnel to the secondary site. This is down without HSRP as the secondary site may be in a different country. DPD and RRI would also be something I wouls like to do at the ASA, so the routes can be dynamically re-injected into OSPF.


Thanks in advance,


Bob James

Correct Answer by Federico Coto F... about 7 years 1 month ago

Same thing.


Federico.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Federico Coto F... Thu, 06/24/2010 - 13:35
User Badges:
  • Green, 3000 points or more

Hi Bob,


The same exact thing is possible in ASAs.


crypto map mymap 10 set peer x.x.x.x y.y.y.y


Federico.

Actions

This Discussion