Solved

ASA5505 - configuring only specific interfaces for L2L VPN tunnel

Posted on 2011-03-04
4
515 Views
Last Modified: 2012-05-11
I have a client with a remote worker that communicates with their corporate office via an ASA 5505 at his house.

The ASA 5505 is connected to the corporate 5520 via an L2L tunnel
All interfaces are currently configured to communicate over the L2L tunnel to the corporate office.

A new request has been received to determine if it is possible to designate four of the seven interfaces on the 5505 to communicate over the L2L tunnel.
The remaining three interfaces would have no knowledge of the tunnel - just a direct connect to the cable modem and out to the internet.

I have attached a cleaned up version of the 5505.

Is this a possible configuration to split up the interfaces of the 5505, or is the device limited to only being able to communicate via the L2L tunnel?
 ASA-5505-cleaned.txt
0
Comment
Question by:techjunky
  • 2
  • 2
4 Comments
 
LVL 8

Accepted Solution

by:
Saineolai earned 500 total points
ID: 35039120
You can place the other four interfaces into a new VLAN and allow this VLAN only to have access to the Internet.  Sort of like a guest internet access zone?
0
 

Author Comment

by:techjunky
ID: 35039360
Got it .....

I've attached an alternate configuration along these lines.

Updates to the original configuration I have noted with   "<--------NEW"

Am I'm missing anything in this new configuration? ASA-5505-alternate.txt
0
 

Author Comment

by:techjunky
ID: 35039399
Looks like the 5505 has a dhcp configuration supplying addresses to the 'inside' interface.

Is there any limitation to setting up a setting dhcp configuration for the 'guest' network?

Current:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside

Proposed:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside
dhcpd address x.x.x.x.-x.x.x.x guest
dhcpd dns x.x.x.x.-x.x.x.x interface guest
dhcpd option 3 ip x.x.x.x interface guest
<dhcp option setting removed - not needed for guest>
dhcpd enable guest
0
 
LVL 8

Assisted Solution

by:Saineolai
Saineolai earned 500 total points
ID: 35039516
Instead of
nat (guest)  2 x.x.x.x x.x.x.x
 use
nat (guest)  1 x.x.x.x x.x.x.x

The dhcp should operate fine also as you have it configured
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
2960 and a VLAN id of 1237 2 60
Issue with seeing default gateway on ASA 5506 firewall 4 47
Some help with Network Design 4 44
Cisco 1811W VLAN configuration problem 3 29
This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question