01-03-2012 07:37 AM - edited 03-07-2019 04:08 AM
Hello everyone,
I currently have the following set up (excuse my quick drawing):
--------------Vendors VPN Router----
| ------Cisco 3000 VPN------ |
| | | |
Private Network-------ASA5510---------Pub Switch------Cisco Router 2x T1
I've been tasked with migrating to the new ISP, which provides us with Cisco ME-3400E switch and /26 public subnet. I currently have 15 static NATs and 14 L-2-L VPN tunnels configured in ASA. Is there a way to configure additional Outside int on ASA and use it to migrate the existing VPN tunnels and static NATs? I'm trying to avoid downtime and hope to do it step by step. I'm thinking about adding additional Public switch, so I can also migrate vendor's router and VPN concentrator, which need to be in parallel to ASA. Assuming that this is possible I'd would like to do the following:
1.Configure and connect additional Outside Interface on ASA - public IP address and ACLs
2.Connect it to additional "Public switch", which would be configured with public IP address and connected to new ISP's Cisco ME-3400E.
3.Migrate my VPN tunnels and static NATs.
4.Migrate vendors equipment/VPN concentrator
5.Update my global NAT pool
6.Shut down old ISP
Is this possible? Any help is greatly appreciated.
Thank you,
forman
01-03-2012 01:22 PM
Yes.This works. The steps you mentioned will work. Make sure to point any static routes on ASA to new outside (outside2) interface when moving the VPN tunnels. However, it is always recomended to make any production changes during the mainteanance window.
hth
MS
01-05-2012 01:28 PM
So this is doable without one major cut-over/downtime? For instance, migrating one VPN tunnel at the time...Have you been involved in similar scenario?
01-06-2012 10:16 AM
So this is doable without one major cut-over/downtime?
-->Yes but there is minor disruption involved when you change VPN peer IPs & routes.
Have you been involved in similar scenario?
I moved to new ISP in one Maintenenace window.
All the best.
Thx
MS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide