Kerry Cordero
  • Facebook
  • Google
  • Linkedin
  • Twitter
  • Rss
  • Home
  • About
  • Blog
  • Documents
    • Cisco
      • GBICS
      • IOS Packaging (formerly IOS Naming)
      • Integrated Service Routers Quick Look 1800/2800/3800
      • Network Cabling Physical Media Distances
      • Power
      • Router Memory
      • Router Modules Cross Reference
      • Router Performace
      • Switching Performance
      • Voice Density
      • VPN Performance
    • Security
      • Cisco Guide to Harden Cisco IOS Devices
      • Cisco PCI Solution for Retail 2.0 Design and Implementation Guide
      • 2010 2011 Computer Crime and Security Survey
      • 2010 Data Breach Investigations Report
  • Portfolio
    • Photos
    • Videos
      • Drums
  • Downloads
  • Links
  • Contact
Home» Security » Cisco ASA Site-to-Site VPN Tunnel IP Change

Cisco ASA Site-to-Site VPN Tunnel IP Change

Posted on February 22, 2011 by Kerry Cordero in Security

If you or your client is moving from one ISP to another, here’s a four step process on how to change the IP Address for the tunnel. It’s actually four steps on each side of the tunnel.

SITE A (Site that IS changing ISPs):

1. First find all configurations using the OLD IP Segment:

sh run | inc 191.70.100.

2. Using notepad, remove all the configurations with the old IP Addresses/Segment. This will include Statics NATs, ACLs, Names, etc… and change it to the new IP Addresses/Segment.

3. Change the IP Address on the WAN interface.

4. Change the Default Gateway.

Now go over to SITE B’s ASA.

SITE B (Site that is NOT changing ISPs):

1. Add the new peer:

crypto map vpnmap 60 set peer 88.100.200.66

2. Remove the old one:

no crypto map vpnmap 60 set peer 191.70.100.22

3. Create the tunnel-group with the pre-shared key:

tunnel-group 88.100.200.66 type ipsec-l2l
tunnel-group 88.100.200.66 ipsec-attributes
pre-shared-key c1scoK3y

4. Remove the old tunnel-group:

clear configure tunnel-group 191.70.100.22

That’s it. The tunnel should go up when you send some packets through the tunnel.

asa, notes, vpn

Comments are closed.

Categories

  • Application Networking Services
  • Laptops, Tablets, & Smart Phones
  • Routing & Switching
  • Security
  • Servers & Desktops
  • VOIP & QOS
  • Wireless

Tags

apple asa bandwidth bgp cables CCIE ccie-rs cidr cisco cya datacenter default design dns frame-relay GNS3 igp ios ipv4 ipv6 juniper module_wics mpls multicast nmap notes oer password pfr pix power proxy qos recovery spanning-tree ssh tips troubleshooting upgrade video vlans vlsm voice vpn windows

(c) 2012 Kerry Cordero