VPN Trunk Between Cisco ASA 5520 and DrayTek Vigor 2930

Posted by David Heggie on Server Fault See other posts from Server Fault or by David Heggie
Published on 2012-01-26T14:32:51Z Indexed on 2012/11/27 23:11 UTC
Read the original article Hit count: 426

Filed under:
|
|

I'm a bit of a VPN newbie, so please go easy on me ...

I'm trying to use the VPN trunking capabilities of the DrayTek Vigor 2930 firewall to bond two IPSec VPN connections to a Cisco ASA 5520 device and I'm getting myself tied in knots and hope someone here with more knowledge / experience can help.

I have a remote site with two ADSL connections and the DrayTek box. The main office site has the Cisco ASA device. I am able to setup a single IPSec connection between the two sites on either of the ADSL connections' public IP addresses, but as soon as I try to use the VPN bonding, nothing works. The VPN tunnels are both still up, but the traffic is getting lost somewhere. I suspect it's due to the ASA not knowing how to route the traffic back over the VPN - one minute, traffic from my remote office's network is coming from public ip address #1, the next it's coming from public address #2 and it doesn't know what to do. Well, that's my newbie impression of what's going wrong, but I don't really know:

  1. If this is really what's happening

  2. If what I'm trying to do (bond two VPN connections from a single remote network to improve the bandwidth / resiliency) is possible with the kit I've got

Could anyone help?

© Server Fault or respective owner

Related posts about vpn

Related posts about cisco-asa