Solved

ASA as gateway for a 2811 router that will be site site VPN

Posted on 2012-03-28
2
330 Views
Last Modified: 2012-04-05
Dear Experts,
I am in need to establish a site to site VPN between 2 cisco routers. One router does not have internet access. I need to make our ASA 5505 its gateway to the internet. I need to make the 2811 router visible in the internet. I have an external IP address I can give it in one of the interfaces (fa 0/0).

I am thinking of using one of the interfaces of the ASA5505 as a DMZ for the Cisco 2811. My questions are for the necessary commands to make this happen in both devices. Is this possible?
Here is an illustration attempted of what the idea looks like.

---voice and data --SA-router 2811¿----¿ ASA5505     VPN   internet  VPN    ASA5510 ¿--¿                                            
                                                                         HOU-router---voice and data traffic            

I only need this for one router by the way. I am more challenge in the asa5505 part.

We tried the site to site VPN between the firewalls but it didn’t work.

Regards, M
0
Comment
Question by:marceloNYC
2 Comments
 
LVL 2

Accepted Solution

by:
gbblaster earned 500 total points
Comment Utility
There is no reason why a VPN between the firewalls wouldn´t work. Can you post the crypto map and isakmp settings along with the ACL that you associated with the tunnel?

If you gave up on the ASA---ASA VPN, then all you´d need to do on the ASA to assign a public IP address to the router  is a static translation on the ASA

static (DMZ,Outside) {public address} {internal router address}

then open inbound permits on the ASAs outside ACLs for vpn traffic wich include:

Protocol ESP
UDP 500
UDP 4500
0
 

Author Comment

by:marceloNYC
Comment Utility
today what we are going to do is place a switch between the ISP and the firewall to split the internet access. That is how we are going to make the Router visible to the internet. Once is working will let you know.
0

Featured Post

Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

Join & Write a Comment

Suggested Solutions

Is your computer hacked? learn how to detect and delete malware in your PC
Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now