How to connect Cisco ASA devices to Azure VPN?

How to connect Cisco ASA devices to Azure VPN?

Virtual network and VPN gateway information Parameter Value Virtual network address prefixes 10.11.0.0/16 10.12.0.0/16 Azure VPN gateway IP Azure_Gateway_Public_IP On-premises address prefixes 10.51.0.0/16 10.52.0.0/16 On-premises VPN device IP OnPrem_Device_Public_IP

How to configure ASA to send traffic to Azure?

Configure static routing – statically configure routes on both the ASA and Azure. Configure the ASA to send traffic to the Azure networks over the VTI tunnel. Modify the Remote Virtual Network Gateway created in Step 4. with networks behind the ASA by adding the prefixes under the “Add Additional Network Spaces” section.

Can you use a VPN with Microsoft Azure?

With VPN’s into Azure you connect to a Virtual Network Gateway, of which there are TWO types Policy Based, and Route Based. This article will deal with Policy Based, for the more modern Route based option, see the following link; Microsoft Azure ‘Route Based’ VPN to Cisco ASA.

How to establish site to site VPN in azure?

In this blog we’ll provide step-by-step procedure to establish site-to-site VPN (with Static Routing VPN Gateway) between Cisco ASA and Microsoft Azure Virtual Network. Before we move on to configure site-to-site VPN, let’s make sure we have the minimum prerequisites to establish site-to-site VPN.

Can a Cisco ASA 5505 be used as a VPN?

Firstly, the implementation of a Route-based VPN with an ASA 5505 requires the use of Traffic Policy Selectors. When configured, this requires you to define a custom IPSec Policy in Azure for the connection and then apply the policy and the Use Traffic Policy Selectors option to the connection.

Is the Cisco ASA 5505 compatible with IKEv2?

For the ASA 5505, we need to ensure that it is running ASA OS 8.4 or above; this added supported to IKEv2 which is a requirement for Route-based connections to Azure.

What do you need to know about Cisco ASA devices?

The sample requires that ASA devices use the IKEv2 policy with access-list-based configurations, not VTI-based. Consult your VPN device vendor specifications to verify that the IKEv2 policy is supported on your on-premises VPN devices. Azure VPN gateways use the standard IPsec/IKE protocol suites to establish Site-to-Site (S2S) VPN tunnels.