AWS BGP VPN to ASA (CiscoASAv)

แชร์
ฝัง
  • เผยแพร่เมื่อ 27 ม.ค. 2025

ความคิดเห็น • 36

  • @fuzzzy17
    @fuzzzy17 2 ปีที่แล้ว

    Amazing explanation with live troubleshooting. Very clear and to the point. Thank you so much!

  • @mohammedmustafaali1049
    @mohammedmustafaali1049 2 ปีที่แล้ว

    you always got me boss,,, thanks from my heart

  • @yb-pq8ry
    @yb-pq8ry 3 ปีที่แล้ว

    excellent video sir!

  • @muhammadhd9558
    @muhammadhd9558 3 ปีที่แล้ว

    So you make the IPSEC connection on the ASA that is already in the AWS side not on the Onpremises Network as you were doing the configuraiton for your testing the AWS ASA with the Public ip 13.X.X.X ?

    • @tendaimusonza9547
      @tendaimusonza9547  3 ปีที่แล้ว +1

      That's correct i launched an ASA from the AWS market place in a different VPC ,and you may do that from a different account as well .the concept is the same as on-premise ASA.

  • @GhostyZA
    @GhostyZA 4 ปีที่แล้ว

    amazing!
    very well explained Tendai!

  • @sreefriend7k7
    @sreefriend7k7 2 ปีที่แล้ว

    I am beginner to ASA. I googled but no luck.
    I am facing this error:
    ciscoasa(config)# crypto ikev1 enable outside
    ^
    ERROR: % Invalid input detected at '^' marker.
    ciscoasa(config)#
    Can you help me please?
    Thanks a lot!

  • @tinashemachona5461
    @tinashemachona5461 4 ปีที่แล้ว +1

    Very informative

  • @azatkhan4714
    @azatkhan4714 2 ปีที่แล้ว

    Thank you! and respect.

  • @johannesmakgopa618
    @johannesmakgopa618 4 ปีที่แล้ว

    Nice one my leader 👏

  • @nivi3418
    @nivi3418 4 ปีที่แล้ว

    My SME! Well done!

  • @dokotella
    @dokotella 4 ปีที่แล้ว

    Thank you for sharing Leadership

  • @augustinasthanyane1494
    @augustinasthanyane1494 3 ปีที่แล้ว

    Nice one Brother. Tnx

  • @foladaramola9815
    @foladaramola9815 3 ปีที่แล้ว

    Hi Tendai,
    How did you log in to the ASA console? Do you have to have a cisco account to do that?

    • @tendaimusonza9547
      @tendaimusonza9547  3 ปีที่แล้ว

      If you do not have a physical ASA you may use an on frial trial or on demand one from the AWS Market place ,Remember to remove the subscription when done else you will billed continuously until you do so .Take note that terminating the firewall instance is not the same as removing a subscription

    • @foladaramola9815
      @foladaramola9815 3 ปีที่แล้ว

      @@tendaimusonza9547 Thank you!

  • @codyshamloo3505
    @codyshamloo3505 3 ปีที่แล้ว

    Thank you Tendai.

  • @eddiemutyori510
    @eddiemutyori510 4 ปีที่แล้ว +1

    Well explained

  • @foladaramola9815
    @foladaramola9815 3 ปีที่แล้ว

    Excellent video. Thank you, Tendai!
    I have a question: How can i set up multiple AWS machines so they can connect to customer network. I was wondering if i'd have to create multiple IAM users and grant them permission to the main account that was used to set up the configuration. Those users can then access the account and use the vpn configured to connect to the customer's network. Right?

    • @tendaimusonza9547
      @tendaimusonza9547  3 ปีที่แล้ว

      Thank you for your the support ,if you are happy hit that subscribe button to grow the channel. I am not clear why you mentioned IAM users however you can connect with me via linkedin :www.linkedin.com/in/tendai-musonza-a9914523 for further discussions and clarity on your use case.

  • @phyll6623
    @phyll6623 3 ปีที่แล้ว

    Hi Tendai, excellent video, I have done the same config, but the BGP peering go down after 1 hour. The IPSec still up, but the VTI tunnel seems to loose connection. The only way to bring the bgp up again, is to shut/un-shut the tunnel interfaces.

    • @phyll6623
      @phyll6623 3 ปีที่แล้ว

      Have you seen this issue before ? On the logs I’ve got BGP hold time expired message.
      I’ve also checked the vti interfaces, when the problem happens, I can’t Ping the other side of the /30. The interface status keep on UP/UP.
      After shut/un-shut the tunnel became alive again..

    • @tendaimusonza9547
      @tendaimusonza9547  3 ปีที่แล้ว +1

      @@phyll6623 , is your phase 2 timer set to 3600 which is also 1 hr .if so it sounds to me like an issue on phase 2 renegotiation / rekey. do you see the ipsec up on Cisco or aws side ,aws console up/status is not really realtime

    • @phyll6623
      @phyll6623 3 ปีที่แล้ว

      @@tendaimusonza9547 I see the tunnel up on ASA side, on AWS took some time to refresh.

    • @phyll6623
      @phyll6623 3 ปีที่แล้ว

      I’ll keep searching for the issue, thank you for raising possible phase2 rekey, I’ll check for this. 👍🏼

    • @tendaimusonza9547
      @tendaimusonza9547  3 ปีที่แล้ว

      @@phyll6623, if you have support you may ask aws to check the logs at those times intervals ,in some cases I have seen devices maintaining old SPIs after rekey. or you can run an ipsec debug towards end of the hour as well .that can help.