cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
244
Views
0
Helpful
2
Replies

site to site vpn - why do I need dauflt gateway when outside interface of 2 ASA are on the same network

asmskabir.khan
Level 1
Level 1

Hi,

why do I need default gateway for 2 ASA for site2site VPN to work. I do understand if the outside interfaces of these 2 ASA have public ip (as it would be in real world), then I need default gateway for those 2 ASA.

2 Replies 2

Rahul Govindan
VIP Alumni
VIP Alumni

In this scenario, you do not need default gateway for the public ip addresses to reach each other, i.e; 192.168.0.20 to reach 192.168.0.30. But you need to force the traffic from 10.0.0.0/24 to 10.1.0.0/24 to hit the outside interface. ASA triggers/initiates the VPN when it sees the interesting traffic to be encrypted. Without default route, the 10.0.0.0/24 network does not know how to reach the 10.1.0.0/24 network. Hope this helps.

Thank you Rahul for your reply.