Solved

L2L tunnels between three sites with ASAs

Posted on 2013-11-11
4
299 Views
Last Modified: 2013-11-14
I am in the planning stages for a 3 site deployment where I would have Sites A, B, C. Site A is the main site and sites B and C will access internet through Site A.

I want all traffic other than local to be routed through the main site (A) however, site B needs to access 2 servers at site C and I would rather route that traffic on a tunnel between B and C.

My question is.... how can I tell the ASA to send traffic for x.x.x.x and y.y.y.y to tunnel BC and everything else to tunnel AB?
I am a little confused by this setup. Basically I would setup interesting traffic for tunnel BC to be x.x.x.x and y.y.y.y but since tunnel AB will route everything else, what would I set that up to be?

                    Site B===============Site C
                       \                                       /
                         \                                   /
                           \                               /
                             \                           /  
                               \                       /
                                 \     Site A    /
0
Comment
Question by:troubleshooter141
  • 2
  • 2
4 Comments
 
LVL 19

Accepted Solution

by:
Kash earned 500 total points
ID: 39638869
i take it site b and c will have have their own internet connections as it is a basic necessity for this setup to work.

can you not create a direct site link from b to c as a separate connection and then have another connection for site A
0
 
LVL 3

Author Comment

by:troubleshooter141
ID: 39639114
yes you're corrent, each site will have their own internet connection, however in order to enforce certain policies I want all internet traffic to go through site A.

Each location will have 2 tunnels, one to each site. For instance, Site A will have a tunnel to site B and a tunnel to site C, site B will have a tunnel to site A and a tunnel to site C and site C will have a tunnel to site A and a tunnel to site B.
0
 
LVL 3

Author Closing Comment

by:troubleshooter141
ID: 39648852
I resolved this. Assigning points to the only answer received, although it wasn't what I was looking for and what ultimatelly resolved the issue.
0
 
LVL 19

Expert Comment

by:Kash
ID: 39649220
do you mind sharing what did you do for a reference and knowledgebase.
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question