A) Setup the VPN on the ASA to use primary and secondary ISP links
for VPN redundancy
B) Setup the remote VPN endpoints to use the headend ASA’s primary and
secondary ISP links as VPN peers (whichever is active)
C) Setup ISP redundancy with for example, SLA monitoring
Now given that we are using two interfaces “Primary” and “Secondary”,
we need to mention these as peer Ip addresses on the remote end, as shown below :
crypto map Outside_map 20 match address crypto-acl
crypto map Outside_map 20 set peer 10.10.10.1 20.20.20.1
(Which means, the primary set peer value is 10.10.10.1,
and if is down, device will try for 20.20.20.1 ip address for tunnel)
crypto map Outside_map 20 set transform-set ESP-3DES-MD5
After this, we need to setup pre-shared keys for ip addresses of both primary
and secondary ISP interfaces on the Headend ASA,
Since when a connection is needed to either primary or secondary interface
ip address, we should have a tunnel-group with matching pre-shared key to
complete the ISAKMP negotiation:
tunnel-group 172.16.10.1 type ipsec-l2l
tunnel-group 172.16.10.1 ipsec-attributes
pre-shared-key *
!
!
tunnel-group 172.16.20.1 type ipsec-l2l
tunnel-group 172.16.20.1 ipsec-attributes
pre-shared-key *
interface Ethernet0/0
nameif primary
security-level 0
ip address 172.16.10.1 255.255.255.0
!
interface Ethernet0/1
nameif backup
security-level 0
ip address 172.16.20.1 255.255.255.0
!
!
route primary 0.0.0.0 0.0.0.0 172.16.10.10 1
route backup 0.0.0.0 0.0.0.0 172.16.20.10 254
!
sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10
!
sla monitor schedule 123 life forever start-time now
!
track 1 rtr 123 reachability
Use-Cases:
===========================================
- Primary ISP is up and running, with this the VPN will be formed
with the “Primary” interface, because the SLA monitoring refereed
under Part 1 above, will put the route,
“route Primary 0.0.0.0 0.0.0.0 172.16.10.10 1” into effect for routing
packets, and the “crypto map VPN-map interface Primary”
will be chosen. - If the Primary ISP goes down, then the SLA monitoring will detect that
the Primary ISP is down and the route
“route Backup 0.0.0.0 0.0.0.0 172.16.20.10 254” will be chosen.
With this the “crypto map VPN-map interface Backup” entry will take effect
because this is the outgoing interface that will be chosen for VPN traffic. - If the Primary ISP comes back up now, SLA tracking will detect this
and the route “route Primary 0.0.0.0 0.0.0.0 172.16.10.10 1” &
“crypto map VPN-map interface Primary” will be chosen and
Primary ISP will be chosen for VPN tunnel negotiations.
Comments
(There are currently no comments for this post.)