Re: terminating IPSec vpn on multiple interfaces



On Mar 3, 10:53 pm, curtislamast...@xxxxxxxxx wrote:
I have a company that is needing to do this as well. Today, my
associate got some bad support from a Cisco TAC person in the manner
of rudeness and they were not very helpful. Enough of that... We have
a single ASA 5510 w/o Security Plus License and we need to terminate
IPSEC on the second interface for RA clients. It's workable when we
know where they are coming from (IP Wise) but RA clients are pretty
much dynamic so putting in a route for them is an admin nightmare. I
have this working at another client site with a static endpoint for a
L2L IPSEC connection. My question is, how do I dynamically add routes
based on the interface in which the traffic was initiated by the RA
clients? The RA client will work just fine if I put a route for my
outside IP address to use the second connections default gateway
address. Any Ideas?

look up IPSEC reverse route injection
.



Relevant Pages

  • Re: terminating IPSec vpn on multiple interfaces
    ... IPSEC on the second interface for RA clients. ... much dynamic so putting in a route for them is an admin nightmare. ...
    (comp.dcom.sys.cisco)
  • Re: terminating IPSec vpn on multiple interfaces
    ... IPSEC on the second interface for RA clients. ... much dynamic so putting in a route for them is an admin nightmare. ... L2L IPSEC connection. ...
    (comp.dcom.sys.cisco)
  • Re: RRAS VPN client doesnt get route update
    ... Where does the client get this route change from? ... > to my network. ... some clients don't update their routing ... > connection the default gateway" because the admin net does ...
    (microsoft.public.windows.server.networking)
  • Re: Urgent RRAS wont work Help!
    ... Where you need the extra routing is on the firewall. ... route but whatever config I use it won't route. ... The clients on the ... network have the default gateway set as 184.155.0.80 via DHCP. ...
    (microsoft.public.win2000.ras_routing)
  • Re: Looking for pointer to VPN / IPSEC info
    ... to be able to access my network while traveling. ... At work the problem is solved with an IPSEC VPN client that I run to connect ... clients built in. ... We usually use OpenVPN rather than IPSec as it's generally easier ...
    (freebsd-questions)