cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
535
Views
0
Helpful
1
Replies

ASA 5520 Spoke to Spoke VPN

ricey
Level 1
Level 1

I am planning to use ASA 5520 as the hub for a hub / spoke VPN. With the spoke to spoke vpn confguration where all remote site vpns terminate on the same (outside) interface, will the AIP SSM IPS module be able to inspect traffic from one spoke that bounces off the ASA to a second spoke, or can it only inspect traffic that actually "passes through" the firewall?

1 Reply 1

beth-martin
Level 5
Level 5

ASA diverts packets to AIP SSM just before the packet exits the egress interface (or before VPN encryption occurs, if configured) and after other firewall policies are applied.For more info refer the following URL

http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df98.html#wp1030972