Solved

ASA5505 - configuring only specific interfaces for L2L VPN tunnel

Posted on 2011-03-04
4
514 Views
Last Modified: 2012-05-11
I have a client with a remote worker that communicates with their corporate office via an ASA 5505 at his house.

The ASA 5505 is connected to the corporate 5520 via an L2L tunnel
All interfaces are currently configured to communicate over the L2L tunnel to the corporate office.

A new request has been received to determine if it is possible to designate four of the seven interfaces on the 5505 to communicate over the L2L tunnel.
The remaining three interfaces would have no knowledge of the tunnel - just a direct connect to the cable modem and out to the internet.

I have attached a cleaned up version of the 5505.

Is this a possible configuration to split up the interfaces of the 5505, or is the device limited to only being able to communicate via the L2L tunnel?
 ASA-5505-cleaned.txt
0
Comment
Question by:techjunky
  • 2
  • 2
4 Comments
 
LVL 8

Accepted Solution

by:
Saineolai earned 500 total points
ID: 35039120
You can place the other four interfaces into a new VLAN and allow this VLAN only to have access to the Internet.  Sort of like a guest internet access zone?
0
 

Author Comment

by:techjunky
ID: 35039360
Got it .....

I've attached an alternate configuration along these lines.

Updates to the original configuration I have noted with   "<--------NEW"

Am I'm missing anything in this new configuration? ASA-5505-alternate.txt
0
 

Author Comment

by:techjunky
ID: 35039399
Looks like the 5505 has a dhcp configuration supplying addresses to the 'inside' interface.

Is there any limitation to setting up a setting dhcp configuration for the 'guest' network?

Current:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside

Proposed:
dhcpd address x.x.x.x.-x.x.x.x inside
dhcpd dns x.x.x.x.-x.x.x.x interface inside
dhcpd option 3 ip x.x.x.x interface inside
dhcpd option 150 ip x.x.x.x interface inside
dhcpd enable inside
dhcpd address x.x.x.x.-x.x.x.x guest
dhcpd dns x.x.x.x.-x.x.x.x interface guest
dhcpd option 3 ip x.x.x.x interface guest
<dhcp option setting removed - not needed for guest>
dhcpd enable guest
0
 
LVL 8

Assisted Solution

by:Saineolai
Saineolai earned 500 total points
ID: 35039516
Instead of
nat (guest)  2 x.x.x.x x.x.x.x
 use
nat (guest)  1 x.x.x.x x.x.x.x

The dhcp should operate fine also as you have it configured
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
NSD FAIL 2 102
ASA AnyConnect tunneling 3 32
what is the difference between Cisco catalyst 2960 and Cisco series SG300-52MP? 8 66
RDP ISR4321 Cisco Router 7 23
When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now