Re: [c-nsp] Multi-homed ASA with a virtual interface for IPSec termination

2018-05-29 Thread Garrett Skjelstad
I have a few hundred tunnels on some ASR1002X's no problem MPLS over DMVPN I, too, would hesitate to use an ASA/NGFW as an IPSec headend for S2S. -Garrett On Tue, May 29, 2018, 13:37 Gert Doering wrote: > Hi, > > On Tue, May 29, 2018 at 01:47:14PM +0100, Nick Hilliard wrote: > > Juniper SRX h

Re: [c-nsp] Multi-homed ASA with a virtual interface for IPSec termination

2018-05-29 Thread Gert Doering
Hi, On Tue, May 29, 2018 at 01:47:14PM +0100, Nick Hilliard wrote: > Juniper SRX handles this end of things a good deal better, imho. SRX seems to make a decent router, yes. Why they insist on calling it a "firewall" escapes me, though. gert -- "If was one thing all people took for granted, w

Re: [c-nsp] Multi-homed ASA with a virtual interface for IPSec termination

2018-05-29 Thread Nick Hilliard
Jason Lixfeld wrote on 28/05/2018 22:36: If not, anything else that may do what I’m after? Cisco ASA is very poor at handling dynamic routing, to the point that any requirement that I have these days for firewalls and BGP will automatically rule out ASA as a platform. It still doesn't suppor

[c-nsp] Multi-homed ASA with a virtual interface for IPSec termination

2018-05-28 Thread Jason Lixfeld
Hey all, I want to use BGP to multi-home an ASA that is to be configured as a P2P IPSec head-end. The eBGP stuff is trivial, but what I’m not sure of is how to anchor a /32 that is to be used as the IPSec destination IP that the remote tunnels will point to. Last I looked, ASA didn’t support