Solved

ASA 5510 Assigning multiple IP's on outside interface for VPN

Posted on 2009-07-14
4
720 Views
Last Modified: 2012-05-07
Is it possible to assign a second ip address to the outside interface of an ASA 5510 to use as a VPN endpoint?  I have one P2P VPN that we need to assign another public ip address for.  This is because of a routing issue we have with the same companies web server that we access through our primary ip address.  They cannot route their web traffic and VPN traffic to the same public ip address on our side.

I had thought about some type of VLAN on the outside interface, but I have not been able to find anyone else doing this.  I didn't know if there would be security concerns or if it is even a viable option.  I know I can NAT multiple public ip's to internal hosts, but I have not been able to find anything on assigning multiple ip addresses for the ASA to use on one interface.
0
Comment
Question by:cellone
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 13

Accepted Solution

by:
3nerds earned 250 total points
ID: 24853777
The simple answer is you can not do it.

BUT

You could  attempt to vlan the interface and trunk it to a switch.

I can give you snip it of config for that type of setup but I don't have the switch side of things as that is not my area of expertise.

interface Ethernet0/2.997
 description Test Backup Internet Interface
 vlan 997
 nameif outside_backup
 security-level 0
 ip address x.x.x.x 255.255.255.x
!
interface Ethernet0/2.998
 description Test Visitor Interface
 vlan 998
 nameif visitor2
 security-level 2
 ip address x.x.x.x 255.255.255.0
!
interface Ethernet0/2.999
 vlan 999
 nameif DMZ
 security-level 10
 ip address x.x.x.x 255.255.255.0

Regards,

3nerds
0
 

Author Comment

by:cellone
ID: 24856049
I had thought about trying a VLAN but didn't know if there would be any security concerns with it.  I have never read of it being done on a outside interface of an ASA or a switch with a public ip.  

I will try this tomorrow and will post back my results.
0
 
LVL 13

Expert Comment

by:3nerds
ID: 24870118
Let me know

3nerds
0
 

Author Comment

by:cellone
ID: 24870278
That worked, thanks for your help.
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question