Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco ASA 5505s site to site vpn setup on ASDM

Posted on 2013-01-29
3
Medium Priority
?
2,554 Views
Last Modified: 2013-02-04
Hello Experts,

I want to create site to site VPN with 2 Cisco ASA 5505 using ASMD. I'm not good with command lines so i prefer ASDM.

Background:

ASA 5505s
iOS 8.4.2
ASDM 6.4.5

Site-A has static IP and Site-B has dynamic ip

I saw a video online setup it when both side are static. How do i go about setting it up on ASDM when Site-B is on dynamic ip.

When i start the VPN wizard on Site A it asks for peer ip address since Site-B is dynamic should I enter 0.0.0.0? With site B i can just go through entering static ip of Site-A's ASA ip.

Further search online suggest on using crypto map on command line. Is there a way on ASDM?
0
Comment
Question by:jli168
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 750 total points
ID: 38833817
Configure the ezvpn server on the Asa with a static IP address. Configure ezvpn client on the remote/dhcp Asa.

This will allow for a VPN connection between Asa's with only one side having a static IP address.
0
 
LVL 2

Accepted Solution

by:
jli168 earned 0 total points
ID: 38836636
Try going thru ezvpn but having error. It is asking me to remove tunnel group and policy that are in place.

A few trial and errors i was able to get it to work but not using ezvpn. I use site-to-site vpn.

First, i went thru site-to-site vpn wizard using static ip (use the dynamic ip from remote site as static) tunnel is up at that point. Then I goto site-to-site vpn, advanced, crypto maps in configuration. I was able to see the mapping to the remote ip. I delete it and add another with mapping outside interface to dynamic and match the other setting what was static.
0
 
LVL 2

Author Closing Comment

by:jli168
ID: 38850476
Thanks for helping rauenpc
0

Featured Post

Introducing the WatchGuard 420 Access Point

WatchGuard's newest access point includes an 802.11ac Wave 2 chipset, providing the fastest speeds for VoIP, video and music streaming, and large data file transfers. Additionally, enjoy the benefits of strong security as the 3rd radio delivers dedicated WIPS protection!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Will you be ready when the clock on GDPR compliance runs out? Is GDPR even something you need to worry about? Find out more about the upcoming regulation changes and download our comprehensive GDPR checklist today !
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question