Solved

ASA5505 - configuring only specific interfaces for L2L VPN tunnel

Posted on 2011-03-04
4
517 Views
Last Modified: 2012-05-11
I have a client with a remote worker that communicates with their corporate office via an ASA 5505 at his house.

The ASA 5505 is connected to the corporate 5520 via an L2L tunnel
All interfaces are currently configured to communicate over the L2L tunnel to the corporate office.

A new request has been received to determine if it is possible to designate four of the seven interfaces on the 5505 to communicate over the L2L tunnel.
The remaining three interfaces would have no knowledge of the tunnel - just a direct connect to the cable modem and out to the internet.

I have attached a cleaned up version of the 5505.

Is this a possible configuration to split up the interfaces of the 5505, or is the device limited to only being able to communicate via the L2L tunnel?
 ASA-5505-cleaned.txt
0
Comment
Question by:techjunky
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 8

Accepted Solution

by:
Saineolai earned 500 total points
ID: 35039120
You can place the other four interfaces into a new VLAN and allow this VLAN only to have access to the Internet.  Sort of like a guest internet access zone?
0
 

Author Comment

by:techjunky
ID: 35039360
Got it .....

I've attached an alternate configuration along these lines.

Updates to the original configuration I have noted with   "<--------NEW"

Am I'm missing anything in this new configuration? ASA-5505-alternate.txt
0
 

Author Comment

by:techjunky
ID: 35039399
Looks like the 5505 has a dhcp configuration supplying addresses to the 'inside' interface.

Is there any limitation to setting up a setting dhcp configuration for the 'guest' network?

Current:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside

Proposed:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside
dhcpd address x.x.x.x.-x.x.x.x guest
dhcpd dns x.x.x.x.-x.x.x.x interface guest
dhcpd option 3 ip x.x.x.x interface guest
<dhcp option setting removed - not needed for guest>
dhcpd enable guest
0
 
LVL 8

Assisted Solution

by:Saineolai
Saineolai earned 500 total points
ID: 35039516
Instead of
nat (guest)  2 x.x.x.x x.x.x.x
 use
nat (guest)  1 x.x.x.x x.x.x.x

The dhcp should operate fine also as you have it configured
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA 5505 packet drops 14 58
What is an ASP Table on a Cisco ASA? 3 52
snmp v2 configuration on a switch 3 45
Cisco tacacs question 6 33
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question