VPN Trunk Between Cisco ASA 5520 and DrayTek Vigor 2930
- by David Heggie
I'm a bit of a VPN newbie, so please go easy on me ...
I'm trying to use the VPN trunking capabilities of the DrayTek Vigor 2930 firewall to bond two IPSec VPN connections to a Cisco ASA 5520 device and I'm getting myself tied in knots and hope someone here with more knowledge / experience can help.
I have a remote site with two ADSL connections and the DrayTek box. The main office site has the Cisco ASA device. I am able to setup a single IPSec connection between the two sites on either of the ADSL connections' public IP addresses, but as soon as I try to use the VPN bonding, nothing works. The VPN tunnels are both still up, but the traffic is getting lost somewhere. I suspect it's due to the ASA not knowing how to route the traffic back over the VPN - one minute, traffic from my remote office's network is coming from public ip address #1, the next it's coming from public address #2 and it doesn't know what to do. Well, that's my newbie impression of what's going wrong, but I don't really know:
If this is really what's happening
If what I'm trying to do
(bond two VPN connections from a single remote network to improve
the bandwidth / resiliency) is possible with the kit I've got
Could anyone help?