Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

ASA 5510 Assigning multiple IP's on outside interface for VPN

Posted on 2009-07-14
4
713 Views
Last Modified: 2012-05-07
Is it possible to assign a second ip address to the outside interface of an ASA 5510 to use as a VPN endpoint?  I have one P2P VPN that we need to assign another public ip address for.  This is because of a routing issue we have with the same companies web server that we access through our primary ip address.  They cannot route their web traffic and VPN traffic to the same public ip address on our side.

I had thought about some type of VLAN on the outside interface, but I have not been able to find anyone else doing this.  I didn't know if there would be security concerns or if it is even a viable option.  I know I can NAT multiple public ip's to internal hosts, but I have not been able to find anything on assigning multiple ip addresses for the ASA to use on one interface.
0
Comment
Question by:cellone
  • 2
  • 2
4 Comments
 
LVL 13

Accepted Solution

by:
3nerds earned 250 total points
ID: 24853777
The simple answer is you can not do it.

BUT

You could  attempt to vlan the interface and trunk it to a switch.

I can give you snip it of config for that type of setup but I don't have the switch side of things as that is not my area of expertise.

interface Ethernet0/2.997
 description Test Backup Internet Interface
 vlan 997
 nameif outside_backup
 security-level 0
 ip address x.x.x.x 255.255.255.x
!
interface Ethernet0/2.998
 description Test Visitor Interface
 vlan 998
 nameif visitor2
 security-level 2
 ip address x.x.x.x 255.255.255.0
!
interface Ethernet0/2.999
 vlan 999
 nameif DMZ
 security-level 10
 ip address x.x.x.x 255.255.255.0

Regards,

3nerds
0
 

Author Comment

by:cellone
ID: 24856049
I had thought about trying a VLAN but didn't know if there would be any security concerns with it.  I have never read of it being done on a outside interface of an ASA or a switch with a public ip.  

I will try this tomorrow and will post back my results.
0
 
LVL 13

Expert Comment

by:3nerds
ID: 24870118
Let me know

3nerds
0
 

Author Comment

by:cellone
ID: 24870278
That worked, thanks for your help.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sharing same loopback address on different switches 1 47
Server 2012 L2TP VPN Windows client to server 3 27
Cisco WAP POE power 28 118
ASA Tunnel 18 42
Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

766 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question