Solved

L2L tunnels between three sites with ASAs

Posted on 2013-11-11
4
300 Views
Last Modified: 2013-11-14
I am in the planning stages for a 3 site deployment where I would have Sites A, B, C. Site A is the main site and sites B and C will access internet through Site A.

I want all traffic other than local to be routed through the main site (A) however, site B needs to access 2 servers at site C and I would rather route that traffic on a tunnel between B and C.

My question is.... how can I tell the ASA to send traffic for x.x.x.x and y.y.y.y to tunnel BC and everything else to tunnel AB?
I am a little confused by this setup. Basically I would setup interesting traffic for tunnel BC to be x.x.x.x and y.y.y.y but since tunnel AB will route everything else, what would I set that up to be?

                    Site B===============Site C
                       \                                       /
                         \                                   /
                           \                               /
                             \                           /  
                               \                       /
                                 \     Site A    /
0
Comment
Question by:troubleshooter141
  • 2
  • 2
4 Comments
 
LVL 19

Accepted Solution

by:
Kash earned 500 total points
ID: 39638869
i take it site b and c will have have their own internet connections as it is a basic necessity for this setup to work.

can you not create a direct site link from b to c as a separate connection and then have another connection for site A
0
 
LVL 3

Author Comment

by:troubleshooter141
ID: 39639114
yes you're corrent, each site will have their own internet connection, however in order to enforce certain policies I want all internet traffic to go through site A.

Each location will have 2 tunnels, one to each site. For instance, Site A will have a tunnel to site B and a tunnel to site C, site B will have a tunnel to site A and a tunnel to site C and site C will have a tunnel to site A and a tunnel to site B.
0
 
LVL 3

Author Closing Comment

by:troubleshooter141
ID: 39648852
I resolved this. Assigning points to the only answer received, although it wasn't what I was looking for and what ultimatelly resolved the issue.
0
 
LVL 19

Expert Comment

by:Kash
ID: 39649220
do you mind sharing what did you do for a reference and knowledgebase.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
IPv6 and IPv4 Subnetting scheme 4 74
ASA 5505 packet drops 14 55
VLAN Issue 4 67
Strange router problem - can't access hotmail.com 14 35
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question