Solved

ASA5505 - configuring only specific interfaces for L2L VPN tunnel

Posted on 2011-03-04
4
513 Views
Last Modified: 2012-05-11
I have a client with a remote worker that communicates with their corporate office via an ASA 5505 at his house.

The ASA 5505 is connected to the corporate 5520 via an L2L tunnel
All interfaces are currently configured to communicate over the L2L tunnel to the corporate office.

A new request has been received to determine if it is possible to designate four of the seven interfaces on the 5505 to communicate over the L2L tunnel.
The remaining three interfaces would have no knowledge of the tunnel - just a direct connect to the cable modem and out to the internet.

I have attached a cleaned up version of the 5505.

Is this a possible configuration to split up the interfaces of the 5505, or is the device limited to only being able to communicate via the L2L tunnel?
 ASA-5505-cleaned.txt
0
Comment
Question by:techjunky
  • 2
  • 2
4 Comments
 
LVL 8

Accepted Solution

by:
Saineolai earned 500 total points
Comment Utility
You can place the other four interfaces into a new VLAN and allow this VLAN only to have access to the Internet.  Sort of like a guest internet access zone?
0
 

Author Comment

by:techjunky
Comment Utility
Got it .....

I've attached an alternate configuration along these lines.

Updates to the original configuration I have noted with   "<--------NEW"

Am I'm missing anything in this new configuration? ASA-5505-alternate.txt
0
 

Author Comment

by:techjunky
Comment Utility
Looks like the 5505 has a dhcp configuration supplying addresses to the 'inside' interface.

Is there any limitation to setting up a setting dhcp configuration for the 'guest' network?

Current:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside

Proposed:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside
dhcpd address x.x.x.x.-x.x.x.x guest
dhcpd dns x.x.x.x.-x.x.x.x interface guest
dhcpd option 3 ip x.x.x.x interface guest
<dhcp option setting removed - not needed for guest>
dhcpd enable guest
0
 
LVL 8

Assisted Solution

by:Saineolai
Saineolai earned 500 total points
Comment Utility
Instead of
nat (guest)  2 x.x.x.x x.x.x.x
 use
nat (guest)  1 x.x.x.x x.x.x.x

The dhcp should operate fine also as you have it configured
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
This video discusses moving either the default database or any database to a new volume.
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now