Solved

Installing pfsense after cisco ASA for VPN only

Posted on 2014-04-01
3
1,436 Views
Last Modified: 2014-04-07
As the title suggests, I'm thinking about adding VPN capability to my site, for IT use only.  I want to stay away from the expensive Cisco vpn licenses and complicated setup.  This is only as a test right now.. But I'm wanting to know how difficult it'd be to configure a box running PfSense and place it inside the network and fwd ipsec VPN requests to it.

has anyone done this before or experienced enough to tell me if this will work and if not why?

Thanks
0
Comment
Question by:Ben Hart
3 Comments
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39969948
Routing might be an issue, if the pfSense box is on the same subnet as the computers to be accessed, if you're thinking IPSec.
A bridged openvpn solution might be easier, with more features (remote wake-on-lan, ARP checks, etc.), but it'll be slightly lower bandwidth.
Doesn't the ASA provide a limited number of VPN connections by default?
0
 
LVL 14

Author Comment

by:Ben Hart
ID: 39969973
I believe the ASA as its configured right now is limited in vpn connections. Honestly though I am looking at this for myself only. Our main site is where all current vpn connections terminate. In the event of downtime as we had two days ago with a large ATT fiber being cut, I had no remote access to my site whose internet access was not affected.
0
 
LVL 1

Accepted Solution

by:
Marty Block earned 500 total points
ID: 39970096
This should be fairly easy . PFSense has a vpn wizard.. Assume that your cisco firewall will allow you to pass a public ip through the firewall to just one physical port on the ASA firewall. I suggest this because if you do a NAT you may have trouble with the VPN connection because of the actual IP (that is public) for vpn connection will not be the 'real' ip on the public side of the PF sense firewall. In this case you may find it necessary to use the public ip on the pf sense in place of the translated NAT ip.. in any event the pfsense wizard will take you through the process of creating the rules and the bridg-able ip space you need for the connection, and I think there is a separate wizard to create the self signed certs you need for the process.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question