We have two sites that are joined by a VPN over two WAN links, one primary and one backup only. The VPN endpoints are a pair of active/standby ASA clusters at each site.
Each site also has multiple additional VPNs to minor sites, some of which are also dual path, again one primary and one backup only.
We have this working although it is not working well, i.e. I'm unable to create new VPNs to new remote sites as they come on line.
I've redesigned the setup but the design made use loopback interfaces, and I now know that ASAs don't support loopback interfaces. I've tried to workaround this by have a dummy sub-interface on the "redundant" interface that trunks the links to the WAN links. Needless to say, this hasn't been successful.
Has anyone else had this problem and have a solution that they can share?
Thanks
CC
0 Answers