Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

ASA5505 - configuring only specific interfaces for L2L VPN tunnel

Posted on 2011-03-04
4
516 Views
Last Modified: 2012-05-11
I have a client with a remote worker that communicates with their corporate office via an ASA 5505 at his house.

The ASA 5505 is connected to the corporate 5520 via an L2L tunnel
All interfaces are currently configured to communicate over the L2L tunnel to the corporate office.

A new request has been received to determine if it is possible to designate four of the seven interfaces on the 5505 to communicate over the L2L tunnel.
The remaining three interfaces would have no knowledge of the tunnel - just a direct connect to the cable modem and out to the internet.

I have attached a cleaned up version of the 5505.

Is this a possible configuration to split up the interfaces of the 5505, or is the device limited to only being able to communicate via the L2L tunnel?
 ASA-5505-cleaned.txt
0
Comment
Question by:techjunky
  • 2
  • 2
4 Comments
 
LVL 8

Accepted Solution

by:
Saineolai earned 500 total points
ID: 35039120
You can place the other four interfaces into a new VLAN and allow this VLAN only to have access to the Internet.  Sort of like a guest internet access zone?
0
 

Author Comment

by:techjunky
ID: 35039360
Got it .....

I've attached an alternate configuration along these lines.

Updates to the original configuration I have noted with   "<--------NEW"

Am I'm missing anything in this new configuration? ASA-5505-alternate.txt
0
 

Author Comment

by:techjunky
ID: 35039399
Looks like the 5505 has a dhcp configuration supplying addresses to the 'inside' interface.

Is there any limitation to setting up a setting dhcp configuration for the 'guest' network?

Current:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside

Proposed:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside
dhcpd address x.x.x.x.-x.x.x.x guest
dhcpd dns x.x.x.x.-x.x.x.x interface guest
dhcpd option 3 ip x.x.x.x interface guest
<dhcp option setting removed - not needed for guest>
dhcpd enable guest
0
 
LVL 8

Assisted Solution

by:Saineolai
Saineolai earned 500 total points
ID: 35039516
Instead of
nat (guest)  2 x.x.x.x x.x.x.x
 use
nat (guest)  1 x.x.x.x x.x.x.x

The dhcp should operate fine also as you have it configured
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA Tunnel 18 42
Cisco Maximum Prefixes Allowed for Customer 5 33
ASA ISP failover 3 23
snmp v2 configuration on a switch 3 16
How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question