cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2160
Views
0
Helpful
4
Replies

Routing between 2 IPSEC tunnels within same ASA5525

ahmed.fneakher
Level 1
Level 1

Hi

Can you please advice how to route 2 different ACL's belongs to different IPSEC tunnels within same ASA so that ACL of firewall A can reach ACL of firewall C using existing tunnel between B and C

(firewall B can route the traffic between A and C) without using DMVPN

2 Accepted Solutions

Accepted Solutions

You do not need to have the same security parameters on the 2 tunnels.

As long as the tunnels between A - B and B - C are working you should be fine.

View solution in original post

Hi Bogdan

Thanks for Support bro.

Tunnel worked,

- No need to match the ACL's for the 3 FW's

- routing from FW B , outside to outside 

- There was issue in ACL of FW A, We just remove and apply it again and everything worked just fine 

- Note that tunnel between A&B was IKEv1 and B&C IKEv2

 

Thanks :)

View solution in original post

4 Replies 4

Bogdan Nita
VIP Alumni
VIP Alumni

Hi Ahmed,

For ASA A and C you will need to add the respective destinations to the crypto acls.

ASA B will need to do hair pinning for the VPN traffic, so it will need to have the both destinations 2.2.2.2 and 3.3.3.3 in the crypto acl. Also on the B ASA you will need to have the same-security-traffic permit intra-interface. Depending on your config you may have to adjust routes and NAT.

Here is a config guide I was able to find:

http://www.packetu.com/2013/04/02/cisco-asa-8-4-vpn-dealing-with-internet-hairpin-traffic/

 

HTH

Bogdan

Thanks Bogdan Nita

What i am understanding (correct me if wrong) that ACL's on 3 ASA should be matched by adding the 2.2.2.2

Also to unify the security parameters (SHA and AES) between the 3 tunnels

in this case, i have to change the tunnel between A and B from IKEv1 to match the tunnel between B and C since the last one is IKEv2

You do not need to have the same security parameters on the 2 tunnels.

As long as the tunnels between A - B and B - C are working you should be fine.

Hi Bogdan

Thanks for Support bro.

Tunnel worked,

- No need to match the ACL's for the 3 FW's

- routing from FW B , outside to outside 

- There was issue in ACL of FW A, We just remove and apply it again and everything worked just fine 

- Note that tunnel between A&B was IKEv1 and B&C IKEv2

 

Thanks :)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: