?
Solved

ASA 5505 Peer Settings, originate only for a redundant peer IP?

Posted on 2014-11-24
2
Medium Priority
?
707 Views
Last Modified: 2014-12-02
I have a 5505 with a vpn tunnel to the main site, this is the primary IP in the crypto map. The redundant IP in the crypto is to another firewall. The thought was that if the primary vpn tunnel goes down, or the primary IP is not reachable for any reason then the 5505 would automatically connect to the secondary redundant IP in the crypto map, the secondary firewall. But, upon further reading it seems that the connection type on the 5505 would need to be set as "connection-type originate-only". Is that true? I had it set as bidirectional. In the ASDM, when you edit the crypto map it says:

 "Uni-directional connection type policies are used for LAN-to-LAN redundancy. Tunnel policies of the "Originate Only" connection type may specify up to 10 redundant peers".

So if my purpose is for the 5505 to connect to a primary 5520, and if that isn't available to connect to another 5520, then I would use the "originate only" on the 5505? Would I change the 2 other crypto maps on the other firewall listening to "answer only"?

crypto map outside_map1 2 match address outside_cryptomap
crypto map outside_map1 2 set pfs group5
crypto map outside_map1 2 set peer "ASA 5520 #1 IP Address" "ASA 5520 #2 IP Address"
crypto map outside_map1 2 set ikev1 transform-set TransformSet
crypto map outside_map1 2 set nat-t-disable


Thanks.
0
Comment
Question by:tolinrome
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 40463977
Whenever I've set this up before - I've never set originate-only and I've not had a problem, though I'm usually seting both peer addresses to two addresses on the SAME firewall (i.e, ISP failover)
0
 
LVL 7

Author Comment

by:tolinrome
ID: 40464450
Thanks, I'll take a look at the article you inserted.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question