Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

site to site VPN peer ip address for failover

Hi,

while creating site to site VPN/IPSec Tunnel on cisco ASA, can we put two peer ip address, one will be primary & other ip wiil be secondary when primary ip will not rechable.

1 REPLY
VIP Purple

site to site VPN peer ip address for failover

You are probably not talking about an ASA-FO-system? There you don't need to configure two peers as the ip address will move to the secondary ASA when the primary fails.

If the two peers are individual boxes, then you can specify two peers in the "set peer" statement of your crypto map. If you use Pre-Shared-Keys, then you also have to configure a second tunnel-group for the backup-peer.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

114
Views
0
Helpful
1
Replies
CreatePlease to create content