Struggling with Site to Site VPN using CiscoASAv and Public Encryption Domains

0

We need to connect from our VPC to multiple partners via Site to Site VPN. Most of our partners can NOT have/connect to private IPs for their encryption domains. Unfortunately, AWS Site to Site VPN does not support this.

We've set up Cisco ASAv according to the instructions and I've been able to establish a test VPN connection, but there are still a couple of issues:

  • We're not sure how to incorporate public IPs into ASAv the configuration. We have 3 EIPs allocated. One is assigned to the ASAv's OUTSIDE interface, which is used as the VPN Peer address. The other two are unassigned. Not sure if I just leave them unassigned and configure them as the public NAT address or If I need to assign them to the OUTSIDE ASAv interface as well
  • We have two EC2 Instances on the INSIDE subnet. How do you change the default gw to be the ASAv's inside IP? If I change the IP config in the EC2 instance from DHCP to Static, I believe it will just change back. It's seems like there would be other issues as well. Should I allocate a second interface to the EC2 and separate the traffic? Is it better to just use static routes for the traffic to the partners? Thanks
drewm
질문됨 2년 전593회 조회
1개 답변
0
profile pictureAWS
지원 엔지니어
답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인