I have a requirement to build a site to site tunnel to my head office from a remote office. My question is, should I use an asa the other end, or should I install a router with a zoned firewall and use a vti tunnel.
Can I create a vti tunnel on a router to the asa in my hq?
You cant run routing protocols over the asa site to site tunnel so I thought a router would be better.
Do you have a private circuit (MPLS, etc..), or just a local Internet circuit at the remote site? If you have both (Internet used as backup for the MPLS), you could terminate the VPN tunnel on an ASA, and then have a primary GRE tunnel over the MPLS, and a secondary (higher cost) GRE tunnel over the backup Internet path.
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
I haven't worked with ASA tunnels, but site-to-site router tunnels work fine, including routing across them. One trick to improve tunnel performance across Internet, don't use link for other than tunnel traffic so that you "know" and can manage the tunnel bandwidth. (If site needs general Internet access, ideally, use another interface.) Also, for an Internet tunnel, you don't need firewall features to secure the tunneling router just for site-to-site tunnels.
This is actually a pretty cool feature, i didn't even know it existed until I was looking for a solution to advertise a subnet (prefix in BGP talk), only if a certain condition existed. This is exactly what conditional advertisements does
j ai une question j ai achete un routeur cisco 887VA-k9 , je le configuré avec la configuration ci- dessous
si je le lier avec mon pc portable sur l un de ses ports directement ça marche toute est bien ( la connexion internet + m...
Attached policy provides CLI access to the Cisco 4G router over text messaging. Two files are in the attached .tar file:
2. PDF with instructions on how to load and use the .tcl file.