Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Attention: The Community will be in read-only mode on 12/14/2017 from 12:00 am pacific to 11:30 am.

During this time you will only be able to see content. Other interactions such as posting, replying to questions, or marking content as helpful will be disabled for few hours.

We apologize for the inconvenience while we perform important updates to the Community.

New Member

VPN Failover with backup ISP -- ASA 55xx

I have to implement a failover VPN via a second ISP.

ASA is set up with

int outside1 default route tracked and static IP.

int outside2 default route not tracked metric 2 and dynamic IP :-(

There is a site-2-site IPSEC VPN to a data center..

Now, the customer want to have the VPN up in failover case, too.

I can think of:

1. dyn DNS :-(

2. Easy VPN with network extension

does anybody has any expieriences either way? or other suggestions??


Re: VPN Failover with backup ISP -- ASA 55xx

Hello Ralf,

As far as I know, ASA does not support DDNS the way you propose. EasyVPN looks like the only option. Your client should be configured as the EzVPN server btw.


New Member

Re: VPN Failover with backup ISP -- ASA 55xx


I did tinker a solution w/ dyndns once, don't like it, tho.

I am not happy w/ ezVPN either. It makes me so unflexible for further VPN's

Just wondering if s.b. has better ideas :-)

CreatePlease to create content