cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
437
Views
0
Helpful
4
Replies

ASA terminate LAN2LAN VPN's on unique addresses

jjaques
Level 1
Level 1

I currently have an ASA5550 terminating 10 LAN2LAN tunnels on one public IP address on the outside interface. Is it possible to terminate each LAN2LAN tunnel with a unique local address? This way if a tunnel needed to be moved to a new ASA the remote LAN2LAN peer would not need to be reconfigured.

4 Replies 4

Ivan Martinon
Level 7
Level 7

Unless you terminate them on a different interface, and configure the routing accordingly your answer would be no.

Hello, thanks for your feedback. I have interfaces that I can use on the ASA. My question is can I configure the additional Gig interfaces as outside interfaces and place them in the SAME subnet/vlan as the current outside interface (bridge them together). I think I have read that the interfaces must EACH be in a separate VLAN and subnet. thanks

same subnet not possible , only option you can use static nat, permitting Ipsec ports.

Hi mkkeyan,

can you explain that configuration in a bit more detail? I understand static NAT and can permit ESP and IKE, but what am I natting?