Solved

ASA 5505 Peer Settings, originate only for a redundant peer IP?

Posted on 2014-11-24
2
548 Views
Last Modified: 2014-12-02
I have a 5505 with a vpn tunnel to the main site, this is the primary IP in the crypto map. The redundant IP in the crypto is to another firewall. The thought was that if the primary vpn tunnel goes down, or the primary IP is not reachable for any reason then the 5505 would automatically connect to the secondary redundant IP in the crypto map, the secondary firewall. But, upon further reading it seems that the connection type on the 5505 would need to be set as "connection-type originate-only". Is that true? I had it set as bidirectional. In the ASDM, when you edit the crypto map it says:

 "Uni-directional connection type policies are used for LAN-to-LAN redundancy. Tunnel policies of the "Originate Only" connection type may specify up to 10 redundant peers".

So if my purpose is for the 5505 to connect to a primary 5520, and if that isn't available to connect to another 5520, then I would use the "originate only" on the 5505? Would I change the 2 other crypto maps on the other firewall listening to "answer only"?

crypto map outside_map1 2 match address outside_cryptomap
crypto map outside_map1 2 set pfs group5
crypto map outside_map1 2 set peer "ASA 5520 #1 IP Address" "ASA 5520 #2 IP Address"
crypto map outside_map1 2 set ikev1 transform-set TransformSet
crypto map outside_map1 2 set nat-t-disable


Thanks.
0
Comment
Question by:tolinrome
2 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 40463977
Whenever I've set this up before - I've never set originate-only and I've not had a problem, though I'm usually seting both peer addresses to two addresses on the SAME firewall (i.e, ISP failover)
0
 
LVL 7

Author Comment

by:tolinrome
ID: 40464450
Thanks, I'll take a look at the article you inserted.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
SRX240 SYSLOG Setting 6 50
VLANs, Cisco Switch, and Ruckus Wireless AP 2 47
Extending  a subnet 9 36
EIGRP Configuration 2 14
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now