VPN Trunk Between Cisco ASA 5520 and DrayTek Vigor 2930

cisco-asadraytekvpn

I'm a bit of a VPN newbie, so please go easy on me …

I'm trying to use the VPN trunking capabilities of the DrayTek Vigor 2930 firewall to bond two IPSec VPN connections to a Cisco ASA 5520 device and I'm getting myself tied in knots and hope someone here with more knowledge / experience can help.

I have a remote site with two ADSL connections and the DrayTek box. The main office site has the Cisco ASA device. I am able to setup a single IPSec connection between the two sites on either of the ADSL connections' public IP addresses, but as soon as I try to use the VPN bonding, nothing works. The VPN tunnels are both still up, but the traffic is getting lost somewhere. I suspect it's due to the ASA not knowing how to route the traffic back over the VPN – one minute, traffic from my remote office's network is coming from public ip address #1, the next it's coming from public address #2 and it doesn't know what to do. Well, that's my newbie impression of what's going wrong, but I don't really know:

  1. If this is really what's happening

  2. If what I'm trying to do
    (bond two VPN connections from a single remote network to improve
    the bandwidth / resiliency) is possible with the kit I've got

Could anyone help?

Best Answer

Been looking at the trunked VPN and from my understanding you have to have two draytek units - one at each end to use this.