VLAN over VPN (ASA 5520)? if not any other options available

cisco-asaipsecisakmpvlanvpn

Is it possible to extend the local VLANs to a Remote site connected by IPSEC VPN using ASA 5520 / Cisco 1841 DSL router.

can we have many VPN tunnels between the ASAs? (from every VLAN one vpn each?)

if not any other options/combinations available?

Best Answer

Is it possible to extend the local VLANs to a Remote site connected by IPSEC VPN

No, per definition. IpSec is an IP level security tunnel. Vlans are ethernet level.

can we have many VPN tunnels between the ASAs

Yes. This is a maintenance nightmare if it gets too much and is not automated in management, but it is possible.

if not any other options/combinations available?

If you put up an ethernet tunnel between them - not sure this is possible - you can then use the "normal" VLAN packets.

http://www.cisco.com/en/US/docs/ios-xml/ios/interface/configuration/xe-3s/ir-eogre.html

has some information, though I am not sure this works on the 1841. But this would allow you to basically send ethernet frames with VLAN information embedded.

Alternatively a multi routing table setup may work - depends on WHY you have VLANS in the first place. or something based on MPLS - VPLS. The 1841 does not talk that one though.

More professional routers may allow something like NVGRE for that purpose. Well, not exactly professional - but the 1841 is more an edge level router not something to use in the core.

It seems that the 1841 can do VPLS - that would work best then. Requires you to configure a MPLS setup.

Main problem answering is that a lot of the choices depends on what you actually try to do from a business point of view and how much control you have over the routers at each endpoint.