Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA 5520 Spoke to Spoke VPN

I am planning to use ASA 5520 as the hub for a hub / spoke VPN. With the spoke to spoke vpn confguration where all remote site vpns terminate on the same (outside) interface, will the AIP SSM IPS module be able to inspect traffic from one spoke that bounces off the ASA to a second spoke, or can it only inspect traffic that actually "passes through" the firewall?

1 REPLY
Bronze

Re: ASA 5520 Spoke to Spoke VPN

ASA diverts packets to AIP SSM just before the packet exits the egress interface (or before VPN encryption occurs, if configured) and after other firewall policies are applied.For more info refer the following URL

http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df98.html#wp1030972

332
Views
0
Helpful
1
Replies