Advertisement

10.03.2007 at 01:38PM PDT, ID: 22870524
[x]
Attachment Details

Cannot multicast through Cisco ASA VPN tunnel

Asked by 1griffith1 in IPSec Security Protocol, Virtual Private Networking (VPN), Cisco PIX Firewall

Tags: asa, vpn, cisco, multicast, tunnel

I recently replaced a SonicWALL PRO 3060 with a Cisco ASA 5510, and I'm having problems with my VPN tunnels and RIP routing.  My remote sites have SonicWALL TZ170s, and I could have them send RIP v2 multicasts across the VPN connections back to the PRO 3060.  Now that I've replaced the 3060 with the ASA, these multicasts aren't passing through the firewall.  I've read somewhere that ASA don't pass multicasts/broadcasts through VPN tunnels, but haven't been able to find out why or if there is a work-around.

My network looks like this:

(inside network) --- 192.168.1.0/24 --- (inside router) --- 192.168.254.0/30 --- (Cisco ASA) --- Internet --- (remote SonicWALL TZ170) --- 192.168.x.0/24 --- (remote network)

The inside network where my ASA is located has an internal router, but the remote network has no router, just the firewall.

Some of the work-arounds I've seen involve firewalls and inside routers on both ends, but that obviously won't work in my situation.

Is there any simple way to get the ASA to accept RIP v2 multicasts (or v1 broadcasts) through the VPN?  Thanks.Start Free Trial
[+][-]10.04.2007 at 05:24AM PDT, ID: 20013458

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: IPSec Security Protocol, Virtual Private Networking (VPN), Cisco PIX Firewall
Tags: asa, vpn, cisco, multicast, tunnel
Sign Up Now!
Solution Provided By: lrmoore
Participating Experts: 1
Solution Grade: A
 
 
[+][-]10.04.2007 at 08:54AM PDT, ID: 20015199

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.04.2007 at 10:10AM PDT, ID: 20015812

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_1_20070628