Remote site 2 Internet connections...

I have a remote office that currently connects to a data center Central via the VPN Site to Site.  I get a 2nd internet connection like a fall back to the remote desktop.  How to configure the Site to Site VPN working properly so that if the main internet connection goes down, the site switches to the secondary?

On internet connections remotely come from different providers so that they have completely different blocks of public IP addresses.

Central

ASA 5520 8.0 (4)

GIG 0/0 public IP

Remote

ASA 5520 8.4 (1)

GIG 0/0 public IP

Public IP address of concert 0/3 (2nd internet)

On the end of HQ you must enter the new IP address of the ISP (for the remote site) as secondary peer.

On the remote end, you must add SLA so that traffic will be redirected on the second link incase of primary failure.

Search the forum you will find many Ref assignment to this scenario. Here is one...

https://supportforums.Cisco.com/message/3452739#3452739

HTH

MS

Tags: Cisco Security

Similar Questions

  • Remote access over Internet connection problems

    I'm trying to figure out how to get remote access to work via the internet. I used to work and it works very well, but we are also on a local network. I have sent the invitation to someone and the password, but it does not connect. I tried the following:

    • Computer Management / Services / connection manager (manual) remote access & routing and remote access (manual)
    • Windows Firewall / allow a program... / Exceptions / Allow: Remote Assistance & routing and remote access
    • Disabled Norton Firewall

    I have alos got my friend to make sure that its parameters match mine. And I still have no success. Does anyone have other ideas? Alternatively, it won't work because I am trying to connect via the internet?

    Hi nataar, 

    Welcome to Microsoft Answers Forums.

    • What software do you use for remote access?
    • What is the version of Windows installed on the computer?

    If you use Remote Desktop connection in Windows Vista, try the procedure below

    Log your PC computer with an account that has administrator privileges.

    Step 1 open the start menu, right-click on "My computer" and select "Properties". A window with the options and details of the computer opens on your screen.

    Step 2 go to the 'Remote' tab at the top of the window "Properties".

    Step 3 check the box for the option "Allow users to connect remotely to this computer" in the section "Remote Desktop" in the Properties window.

    Step 4: click on the 'Apply' button at the bottom of the window to save the changes and enable the remote desktop. Outside users will now be able to access your computer over the Internet.

    Enabling remote desktop access to your computer

    To activate the Office remote connections to your computer, follow these steps:

    1. Click Start, right-click computer, and then select Properties.
    2. Under tasks, click settings on the remote control and confirm the user account control prompt.
    3. Select allow connections from computers running any Version of remote desktop. (Version 'more safe' only works on using IPSec security, and on these networks business networks, you probably will not be allowed to change these settings in any case).
    4. By default, all administrator-level accounts can connect to the computer. If you want to grant remote desktop access to a limited number of users, click Select users, add, advanced, find now and then find the desired name in the search results section. Double-click it. To add another name, click Advanced and find now again.
    5. Click OK to close the dialog boxes.

    NOTE A password must be set on a user account before the user can connect to the remote computer.

    At this point, you must do two things to make sure that remote desktop has been implemented correctly:

    • Click Start, Control Panel. Under Security, select allow a program through Windows Firewall and confirm the user account control prompt. On the Exceptions tab, find the Office remotely in the list of Exceptions and do not forget, that it is checked. If it isn't, check it out. On the general tab, make sure that block all incoming connections is not checked.
    • Use another computer to test the remote desktop before you get involved in the Internet game. Follow the instructions in the second part of the chapter to open the desktop client remotely on another computer on your network. As the host name, type the name of the computer you just put up. Make sure that you can connect on your own local network before continuing.

    Remote Desktop connection: frequently asked questions

    http://Windows.Microsoft.com/en-us/Windows-Vista/Remote-Desktop-connection-frequently-asked-questions

    Halima S - Microsoft technical support.

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Can I just share my photos via ATV iPhone without internet connection?

    Hi, I am looking to use my iPhone 5 s to display a slide show on my monitor via ATV, but its at a remote site without Wifi connection. All images are stored remotely on the iPhone.  Will be my iPhone still pair for Airplay, just use my Hotspot connection?  Thank you

    The simplest thing to do would be to use a lightning of Apple to the HDMI connector and switch the ATV.

    If you follow the path of the ATV, you need a Wifi network to allow function Airplay.  You can use a hotspot to support this.

    I suggest that you try the hotspot at home by connecting ATV and see what happens.

    I personally bought the adapter and try that as well.  If you don't finish like the solution of the adapter, the Apple Store has a 14 days with no questions return policy.

  • VPN clients cannot access remote sites - PIX, routing problem?

    I have a problem with routing to remote from our company websites when users connect via their VPN client remotely (i.e. for home workers)

    Our headquarters contains a PIX 515E firewall. A number of remote sites to connect (via ADSL) to head office using IPSEC tunnels, ending the PIX.

    Behind the PIX is a router 7206 with connections to the seat of LANs and connections to a number of ISDN connected remote sites. The default route on 7206 points to the PIX from traffic firewall which sits to ADSL connected remote sites through the PIX. Internal traffic for LAN and ISDN connected sites is done via the 7206.

    Very good and works very well.

    When a user connects remotely using their VPN client (connection is interrupted on the PIX) so that they get an IP address from the pool configured on the PIX and they can access resources located on local networks to the office with no problems.

    However, the problem arises when a remote user wants access to a server located in one of the remote sites ADSL connected - it is impossible to access all these sites.

    On the remote site routers, I configured the access lists to allow access from the pool of IP addresses used by the PIX. But it made no difference. I think that the problem may be the routes configured on the PIX itself, but I don't know what is necessary to solve this problem.

    Does anyone have suggestions on what needs to be done to allow access to remote sites for users connected remotely via VPN?

    (Note: I suggested a workaround, users can use a server on LAN headquarters as a "jump point" to connect to remote servers from there)

    with pix v6, no traffic is allowed to redirect to the same interface.

    for example, a remote user initiates an rdp session for one of the barns adsl. PIX decrypts the packet coming from the external interface and looks at the destination. because the destination is one of adsl sites, pix will have to return traffic to the external interface. Unfortunately, pix v6.x has a limitation that would force the pix to drop the packet.

    with the v7, this restriction has been removed with the "same-security-traffic control intra-interface permits".

    http://www.Cisco.com/en/us/partner/products/HW/vpndevc/ps2030/products_configuration_example09186a008046f307.shtml

  • VPN remote as well as Internet connection

    Hello

    We have a Cisco ASA 5512 - X & we have configured the VPN Site to Site (IPsec Tunnel) as well as the distance of Cisco vpn client. Both work correctly.

    problem is that:

    When the remote user vpn client connection, then they are able to access the local corporate network but is not able to access the internet on their local computer.

    I want that, when the user connects client remote vpn as well as its local internet.

    Kindly, help us do.

    Current configuration is attached.

    network object obj - 10.90.5.0
    10.90.5.0 subnet 255.255.255.0

    NAT (inside, outside) source static obj - 192.168.0.0 obj - 192.168.0.0 destination static obj - 10.90.5.0 obj - 10.90.5.0 no-proxy-arp-search to itinerary

    IP local pool testpool 10.90.5.1 - 10.90.5.100 mask 255.255.255.0

    Crypto ipsec transform-set esp-3des esp-md5-hmac ikev1 us_3des
    crypto dynamic-map 1 HOUR set transform-set us_3des ikev1
    card crypto CVPN 1-isakmp ipsec dynamic PRIVATE
    CVPN outside crypto map interface

    IKEv1 crypto policy 1
    preshared authentication
    3des encryption
    md5 hash
    Group 2
    life 86400

    tunnel-group usnlgroup type ipsec-ra
    tunnel-group usnlgroup General-attributes
    address testpool pool
    usnlgroup group of tunnel ipsec-attributes
    IKEv1 pre-shared-key *.

    vinod username password *.

    If the PC loses internet after connecting to the VPN while it must in tunnel-like split-tunnel-politics.

    From your configuration, I see that there is no group configured on the tunnel-group strategy.

    To activate the split tunnel you can use the configuration below

    Note the subnets that you allow on the VPN client. Outside these subnets all other traffic will use local circuit of the internet from your PC.

    Split_Tunnel_List list of standard access allowed

    internal usnlgroup group policy
    attributes of the strategy of group usnlgroup
    Split-tunnel-policy tunnelspecified
    value of Split-tunnel-network-list Split_Tunnel_List

    tunnel-group usnlgroup General-attributes

    Group Policy - by default-usnlgroup

    Reconnect the VPN and then try to access the internet.

  • VPN to use remote internet connection

    Hello

    I'm trying to access a Web site in the Venezuela that is blocking connections from outside Venezuela (official results of the presidential elections Sunday, which are publicly). I have access to remote control a computer running windows 7 to the Venezuela, but I don't want to use remote desktop as connections every time I want to visit this Web page.
    I remember that my school provides VPN access so that we can access documents and others during off-campus research and thought I could use VPN Windows anyway.
    I managed to create the VPN connection using VPN Windows clients/server, but it only allows me to access the internet. If I uncheck the option 'use remote gateway', while my local internet connection will always be recognized as outside the Venezuela. How can I activate the remote computer access to the internet for my local system connected VPN?

    Hello

    The Microsoft Answers community focuses on the context of use. Please join the professional community of COMPUTING in the TechNet forum below

    http://social.technet.Microsoft.com/forums/en-us/category/w7itpro

  • SSL vpn through the same internet connection to another site

    Hi, I have a network with a box of Juniper SSL that connect to port DMZ ASA5510, wher outside the ASA is the same outside the box of SSL vpn.

    To access issues eno hav network internal at all.

    Now, I need VPN SSL Juniper box remote users and internal conenct o my remote sites, who take the client connection through an internet router (Cisco throug site to site vpn IPSec) again to the th eremote site.

    Is it possible, my hunch is Yes "can be done."

    Currently, I'm fitting get no where, I get no hits ASA DMZ ACL if I try to access the remote site of the SSL vpn client resources.

    Schema attached

    Any help would be appreciated

    Shouldn't be a problem.

    On the Juniper SSL, you must check if the roads has been added to the remote IPSec LAN point to the ip address DMZ ASA instead of pointing to the internet through the Juniper SSL box.

    You need to configure NAT exemption on the ASA box between the pool SSL subnet to the Remote LAN of IPSec. As a result, you must also include the SSL subnet to Remote LAN subnets in the crypto ACL and mirror image ACL on the remote site ACL Cryptography.

    Hope that helps.

  • Internet access and VPN remote site?

    Hi all!

    I have a remote site who want to use their own internet connection to access the internet. Just at that moment that I use their router gateway to send all their data on an IPSec tunnel to us (Cisco 831) it connects to a headquarters at 2600. is it possible to have a slot on the remote site, so that surfers IP packets are sent directly to the internet and IP private to the IPSec VPN?

    I have to get more / different HW or a simple change in config?

    I checked Cisco.com but just GRE tunnels where both the tunnel AND out of the interface have the Crypto Card...

    Hello

    You can restore the mode of connectivity with the outside world?

    Also can you confirm if you use any device behind the router coz your LAN network is configured to only 2 usable/configurable ips belonging to 30 mask...

    with this configuration a little you must enable natting who will do the trick for you...

    just include commands in your config below...

    interface Ethernet0/0

    NAT outside IP

    !

    interface Ethernet0/1

    IP nat inside

    !

    IP nat inside source list 1 interface ethernet 0/0 overload

    !

    access-list 1 permit 172.16.222.44 0.0.0.3

    regds

  • I'm getting "connection timed out" when I try to connect to a specific Web site. I can connect to the site using Internet Explorer. Help?

    As suggested by Firefox, I've cleared my history and cache. Also, I downloaded and run one of the programs malicious applications recommended Firefox. I also deleted Firefox my firewall and then added it back as suggested by Firefox. I have no problem accessing the site using Internet Explorer.

    HTTPS Everywhere makes it easy for you to move site to a secure connection. It's something that you can yourself on the sites where you are displaying sensitive information, so it automates this for you, but I think that it is not essential.

    If you love the comfort, the extension has a function to create your own rules, as described on https://www.eff.org/https-everywhere/rulesets. It sounds a little complicated...

  • When connecting them to a secure site on Internet Explorer, it is a 'padlock' symbol so you can see it's course, is there something similar in Firefox? Thank you.

    When connecting them to a secure site on Internet Explorer, it is a 'padlock' symbol so you can see it's course, is there something similar in Firefox? Thank you.

    See this - https://support.mozilla.com/en-US/kb/Site+Identity+Button

  • Internet connected but get the message to check internet connections. Cannot log on to remote servers...

    I am trying to connect to i-tunes and TurboTax.  I am connected to the Internet and can get to the two sites and move in them; However, I can't connect to the itunes store, I get the message of Itunes can't connect to the Itunes store.  The network connection was refused.  I get the message similar to TurboTax.  I was able to connect to both now and and I'm sure many others.  I am also unable to connect Wiindows Live even trouble message with my internet connections.  I need help! I'm to the point that I'm going to put my laptop to factory and lose everything, and I really don't want to do that.

    Hello

    1. what version of Windows is installed on the computer?

    2. what browser you use to access these sites?

    3. If Internet Explorer, what version of IE are you using?

    4. are you aware of any changes made to the computer, before the show?

    Method 1:

    I suggest to add Web sites to the trusted list in Internet Explorer and check.

    Security zones: adding or removing websites

    http://Windows.Microsoft.com/en-us/Windows-Vista/security-zones-adding-or-removing-websites

    Method 2:

    You can try to clear your history of navigation and control.

    Clear the history of websites you've visited

    http://Windows.Microsoft.com/en-us/Windows-Vista/clear-the-history-of-websites-you visited

    Method 3:

    I suggest to reset Internet Explorer and check.

    How to reset Internet Explorer settings

    http://support.Microsoft.com/kb/923737

    Warning: Reset the Internet Explorer settings can reset security settings or privacy settings that you have added to the list of Trusted Sites. Reset the Internet Explorer settings can also reset parental control settings. We recommend that you note these sites before you use the reset Internet Explorer settings

    I hope this helps.

  • I can't get on my hotmail account - internet connects to all other Web sites, but not Hotmail. Any ideas?

    I got in trouble for the week when you log in to my hotmail account. Internet connects to all other sites Web but Hotmail. You have any suggestions to solve this problem. It's really annoying. Thanks adrienne

    After all the Hotmail issues in the appropriate forum found here:
    http://windowslivehelp.com/

  • Not able to connect to a remote site to the Windows XP computer.

    Original title: need help for the remote Office of information...

    .......... A storm disabled the remote site.  This site is now running, but my laptop refuses to connect to the remote site.  What should I do?

    Hi BarbaraAnnH,

    1. you receive any code or an error message when you try to connect to the remote site?

    2 are. what remote you referring?

    You can temporarily disable all security software and check if the problem persists.

    Note: Later, enable the security software after checking.

    Reference: Remote Desktop: frequently asked questions

    Hope the helps of information.

  • Unable to connect to the internet, the error message ' primary DNS server does not and remote Firewall can block connection.

    Original title: Internet connectivity.

    Internet connectivity.  I can't connect to the internet from the computer at home.  Get the message "primary DNS server is online but doesn't react don't not to connection attempts."  Remote Firewall might be blocking connection.  Name of the filter GUIID mfe is connect-legend-v4.  McAfee Firewall is enabled.  Turned it off temporarily with the same result.

    Hello

    Did you change on your computer before the show?

    Follow the steps mentioned below:

    Method 1:

    Network connection problems

    http://Windows.Microsoft.com/en-us/Windows-Vista/troubleshoot-network-connection-problems

    Method 2: Try resetting the TCP/IP stack.
    To reset the stack TCP/IP go to this article and either click on "Fix it for me" or follow the instructions to fix it yourself

    How to reset the Protocol Internet (TCP/IP)

    http://support.microsoft.com/kb/299357 .
    If the same problem still persists, then try the next method.

    Method 3: update the network driver.
    Steps to update of network driver:
    a. click the Start button.
    (b) in the search box type devmgmt.msc and then press ENTER.
    c. Select the network card device and right click on it
    d. now, select Properties.
    e. in the Properties window, on the driver tab, click Update driver.
    f. after the installation of the updates, restart the computer.
    For more information visit:

    Updated a hardware driver that is not working properly

    http://Windows.Microsoft.com/en-us/Windows-Vista/update-a-driver-for-hardware-that-isn ' t-work correctly.
    Method 4: Definition of obtaining DNS on automatic

    a. Click on start and then Control Panel.
    b. go to the networking and sharing Center and then click on change adapter settings.
    c. right-click on connection to the Local network and select Properties.
    d. Select Internet Protocol Version 6, and then click Properties.
    e. Select obtain DNS server automatically an address and press Ok.
    f. Select obtain IP address automatically.
    i. Repeat steps for Internet Protocol version 4 as well.

  • Can I use MSTSC to connect remotely on the internet?

    Can I use MSTSC to connect remotely on the internet (local computer is Vista Ultimate SP2 to a distance Win 2003 Server)? I used MSTSC on my local network and it works well.

    Hi Ibaltsae!

    Thanks for posting. Yes, you can use MSTSC to connect remotely to a computer or server on the internet, the same as if you were using your local network. To connect to the remote computer, use the DNS or public IP that are associated with name.

    I hope this helps! Shawn - Support Engineer - MCP, MCDST
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

Maybe you are looking for

  • Conversion of the discussions of the Forum Pages

    I have contributed on a forum of philosophy for a few years and just downloaded all of my text messages. There is a lot of it! This is a readable text file but he got all the information tag inside, the words in italics and quotes tags around them in

  • Satellite M50-226 with Bluetooth?

    HY guys,.I have a question...I bought a M50-226, which had pre-installed XP Home... In the Device Manager there is a Toshiba Bluetooth something device called RFCOMM... I don't remember exactly.Now, I have installed XP Pro... and follow the installat

  • Causing the Windows Task Manager to Internet problems?

    When I open the Task Manager to change the priority of a program (change by normal normal CPU use above) it causes my ping in games to soar and I get huge lag spikes and possibly disconnect. I am running Windows 7 Ultimate 32 bit. I had no such probl

  • WiFi connectivity - the On / Off button on my Dell Vostro 1310 does not

    I can't have the WiFi button to enable the WiFi connectivity. I tried to update the drivers from the Dell site, but I thought that the material is missing. Any suggestions are welcome. Thank you Mervyn

  • Photosmart D - 110

    My printer replaced black ink cartridge recently, quit printing black.  There is no fbeen an indication of the low level of ink.