02-20-2009 05:28 AM
I currently have an ASA5550 terminating 10 LAN2LAN tunnels on one public IP address on the outside interface. Is it possible to terminate each LAN2LAN tunnel with a unique local address? This way if a tunnel needed to be moved to a new ASA the remote LAN2LAN peer would not need to be reconfigured.
02-26-2009 08:40 AM
Unless you terminate them on a different interface, and configure the routing accordingly your answer would be no.
03-02-2009 12:51 AM
Hello, thanks for your feedback. I have interfaces that I can use on the ASA. My question is can I configure the additional Gig interfaces as outside interfaces and place them in the SAME subnet/vlan as the current outside interface (bridge them together). I think I have read that the interfaces must EACH be in a separate VLAN and subnet. thanks
03-02-2009 03:27 AM
same subnet not possible , only option you can use static nat, permitting Ipsec ports.
03-02-2009 04:07 AM
Hi mkkeyan,
can you explain that configuration in a bit more detail? I understand static NAT and can permit ESP and IKE, but what am I natting?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide