Re: terminating IPSec vpn on multiple interfaces



On Mar 4, 5:05 am, Merv <merv.hr...@xxxxxxxxxx> wrote:
On Mar 3, 10:53 pm, curtislamast...@xxxxxxxxx wrote:

I have a company that is needing to do this as well.  Today, my
associate got some bad support from a Cisco TAC person in the manner
of rudeness and they were not very helpful. Enough of that...  We have
a single ASA 5510 w/o Security Plus License and we need to terminate
IPSEC on the second interface for RA clients.  It's workable when we
know where they are coming from (IP Wise) but RA clients are pretty
much dynamic so putting in a route for them is an admin nightmare.  I
have this working at another client site with a static endpoint for a
L2L IPSEC connection.  My question is, how do I dynamically add routes
based on the interface in which the traffic was initiated by the RA
clients?  The RA client will work just fine if I put a route for my
outside IP address to use the second connections default gateway
address. Any Ideas?

look up IPSEC reverse route injection

Would this apply to site-to-site ipsec terminated on multiple
interfaces?
.



Relevant Pages

  • Re: terminating IPSec vpn on multiple interfaces
    ... IPSEC on the second interface for RA clients. ... much dynamic so putting in a route for them is an admin nightmare. ... L2L IPSEC connection. ...
    (comp.dcom.sys.cisco)
  • Removing gif interface also remove default route.
    ... when I removed the gif (ipsec) interface, the system also remove the default route. ... But in my 6.2-Prelease, there is no problem when removing gif interface. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Holub on getters/setters again
    ... > getter/setter interface, you simply can't implement that solution, so it ... code and how it uses the server methods, rather than focusing on how the ... Especially they might hint to clients implementing operations on ... whenever I modify the implementation of string (for example if I switch ...
    (comp.object)
  • Re: On getters/setters (to Daniel T.)
    ... >> code and how it uses the server methods, ... > might be reasonable to conclude that its clients are working on that data. ... I'm saying that changes to the interface of a class are (or at least ... to server code that would break client code. ...
    (comp.object)
  • Routing between subinterfaces
    ... subinterfaces as the Vlan gateways. ... one interface for all user interaction. ... VLAN 10 clients interface 0/1 ... switchport trunk allowed vlan 20,30 ...
    (comp.dcom.sys.cisco)