Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

ASA VPN Site to site : DMVPN or Full mesh ?

Hi all

I'm fresh man in cisco enviroment, please help me

Currently i'm working on a project that need to set up VPN for security at mutiple site with diffirent ISPs ( not decided static or dynamic IP yet)

I can request Cisco Router for L3 routing devices and ASA appliance also

My target is : all sites can communicate with each others.

Now I'm considering about DMVPN or Full mesh topology

So you guys please answer my questions :

1 - Static IP from ISP is the best right ? Can i use dynamic IP ? ( I know ASA have some kind of dynamic - static VPN )

2 - DMVPN :

     + ASA not support it, but i heard that somehow ASA can config as spoke to spoke VPN. Is that match my target ?

     + Please refer me documents for set it up if you have

3 - Full mesh VPN :

     + How to setup it, am i have to config L2L VPN each sites to the rest ?

4 - DMVPN vs Full Mesh - Which one is better ? which one is less config work, less administration tasks ?

5 - The last one : please consult me the device needed for my target

Thanks you all!

Everyone's tags (3)
1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Super Silver

Re: ASA VPN Site to site : DMVPN or Full mesh ?

You're correct that an ASA will not support DMVPN. It would require you setup individual LAN-LAN VPN tunnels at every site (n x (n-1) tunnels total).

FlexVPN with ISR G2 routers would be the least amount of configuration work and most flexible setup for your stated requirements. It has the advantages of EZVPN and DMVPN together.

There are a number of FlexVPN configuration examples here.

4 REPLIES
Hall of Fame Super Silver

Re: ASA VPN Site to site : DMVPN or Full mesh ?

You're correct that an ASA will not support DMVPN. It would require you setup individual LAN-LAN VPN tunnels at every site (n x (n-1) tunnels total).

FlexVPN with ISR G2 routers would be the least amount of configuration work and most flexible setup for your stated requirements. It has the advantages of EZVPN and DMVPN together.

There are a number of FlexVPN configuration examples here.

New Member

ASA VPN Site to site : DMVPN or Full mesh ?

Thank you for your answer

Now i'm looking at FlexVPN and wondering is it support mobile client ?

My plan is set up multiple site to site for each branch => Solution is Flex VPN, right ?

And also remote client maybe window, android, ios ( iphone devices ) will be connected to branch that can also communicate with other client in other branch. => WebVPN-Anyconnect ASA or Router maybe ?

Please tell me whether Flex VPN can work with WebVPN ?

Thank you

Hall of Fame Super Silver

ASA VPN Site to site : DMVPN or Full mesh ?

An AnyConnect Secure Mobility client (PC- or mobile-based) can establish remote access into a FlexVPN.

WebVPN is also known as clientless SSL VPN and, as such is SSL-based. Since FlexVPN is IKE v2-based, they are not compatible.

New Member

ASA VPN Site to site : DMVPN or Full mesh ?

Thank you for your support

2945
Views
0
Helpful
4
Replies
CreatePlease to create content