Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

what type of vpn connection is allowed on the multimode firewall?

dear expers,

hello

i have two physical firewall and i've created active/active failover on them. so i'd like to know what type of vpn connection i can creat on

those firewalls to administer them remotely.

thaks for your quick responde

makar

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: what type of vpn connection is allowed on the multimode fire

VPN is not supported at all for ASA in multi context mode which is what Active/Active failover required.

Here is the URL for your reference:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/contexts.html#wp1146747

VPN to administer the ASA is supported in transparent firewall, but not in multi context (Active/Active failover). Here is the URL for VPN termination on transparent ASA to administer the firewall:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1222826

3 REPLIES

Re: what type of vpn connection is allowed on the multimode fire

Hi,

I believe you can create either IPsec or SSL VPN to administer the ASA remotely.

Since the ASAs are in multiple context, the VPN is only for administration purposes since in multiple context the ASA cannot act as a regular VPN termination point. But for administration, I believe you can do both.

Federico.

Cisco Employee

Re: what type of vpn connection is allowed on the multimode fire

VPN is not supported at all for ASA in multi context mode which is what Active/Active failover required.

Here is the URL for your reference:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/contexts.html#wp1146747

VPN to administer the ASA is supported in transparent firewall, but not in multi context (Active/Active failover). Here is the URL for VPN termination on transparent ASA to administer the firewall:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1222826

Re: what type of vpn connection is allowed on the multimode fire

I stand corrected! No VPN support on multiple-context mode (only on transparent mode).

Thank you halijeen.

Federico.

288
Views
0
Helpful
3
Replies
CreatePlease to create content