cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
829
Views
0
Helpful
2
Replies

Quick question about 'local network' for ASA 5500 LAN to LAN

cweatherford
Level 1
Level 1

I have to setup access for a support vendor that needs access to just a few IP addresses in my datacenter but all of my branch locations. In the LAN to LAN setup can I enter more than one IP and subnets?

Thanks!

Chad

1 Accepted Solution

Accepted Solutions

rizwanr74
Level 7
Level 7

HI Chad,

"In the LAN to LAN setup can I enter more than one IP and subnets?"

Sure you can, if you are planing to setup land to land IPSec tunne, it is your no-nat and crypto acl can be used to control what are allowed and what not over the tunnel itself.

However if you planing to use a remote-access tunnel instead, it is your "vpn-filter value" and associate it with an ACL and in the example below group name is set as "filter"

group-policy filter internal
group-policy filter attributes
 vpn-filter value 103

Reference:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml

Thanks

Rizwan Rafeek

View solution in original post

2 Replies 2

rizwanr74
Level 7
Level 7

HI Chad,

"In the LAN to LAN setup can I enter more than one IP and subnets?"

Sure you can, if you are planing to setup land to land IPSec tunne, it is your no-nat and crypto acl can be used to control what are allowed and what not over the tunnel itself.

However if you planing to use a remote-access tunnel instead, it is your "vpn-filter value" and associate it with an ACL and in the example below group name is set as "filter"

group-policy filter internal
group-policy filter attributes
 vpn-filter value 103

Reference:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml

Thanks

Rizwan Rafeek

Thanks Rizwan!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: