Solved

Dynamic to static L2L IPSec tunnel - ASA / IOS - Select different group

Posted on 2013-11-06
3
815 Views
Last Modified: 2013-11-26
I have an IOS router with a dynamic IP that I need to have connect to a static ASA for a L2L IPSec tunnel. Config is okay but I need to have this tunnel not land on the DefaultL2LGroup policy. I have seen some mention of the need to use certificates for this to work but I'm having trouble finding a good walkthrough. I need to set up the dynamic side (Cisco IOS router) to somehow let the static side (Cisco ASA) know that this connection needs to be addressed by a different group other than the default.

Thanks!
0
Comment
Question by:farroar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 500 total points
ID: 39631647
Use EZVPN with NEM!

http://www.alfredtong.com/cisco/cisco-ezvpn-cisco-asa-and-ios-router/

I have used this with an ASA 5510 which was on the main office and the vpn client was a CISCO881GW-GN-E-K9 which was roaming around in different countries with different sim cards (and thus ip addresses).

I hope the URL will get you going, if not please let us know!
0
 

Author Comment

by:farroar
ID: 39637032
Thanks for the Link! Seems to be exactly what I need but it doesn't seem to be working. Let me play with it for a bit and get back to you. One thing to note.. the ASA already has many VPNs dynamic and L2L terminating to it. I just need to make sure none of the adjustments I make are global. They can only address this one connection.
0
 

Author Closing Comment

by:farroar
ID: 39679742
Good link. It got me going in the right direction. Thanks!
0

Featured Post

Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question