Hi
I'm in a bit of a predicament and looking for some help. I'm setting up a Site-to-Site VPN for 7 branches, I have most worked out, but one of the branches is giving me nightmares.
I have head office in Cape Town, ADSL connection. 5 other branches with ADSL connection and one branch with 3G connection (no ADSL available).
I want to install a Cisco ASA-5505 at each site, but I need a public IP on one of the VLANs on each device (i can cope with dynamic as I have a server with a static IP at an 8th branch that won't be part of the VPN, I can set up a DDNS server here - the ASA doesn't support HTTP DDNS services so it would have to be IETF unless there's a company out there that's similar to DynDNS.org but uses IETF protocol, any ideas?). Further I can configure the crypto maps to use hostname lookups.
The problem is that ADSL routers can easily be configured in bridge mode and PPPoE configured on the ASAs, same goes for iBurst, but I've never done this with 3G. That's where I need help, can I get a 3G modem with an ethernet port (instead of the standard PC card or USB) and use PPPoE or some other protocol to bridge it? Otherwise, can I use a 3G router for this and disable the routing? I'm a bit clueless, the ASA-5505 only has Ethernet ports.
As a last resort I can probably use a Cisco 881G, as it can establish a tunnel to a Cisco ASA, but I'd be losing on the security features which I don't want to do.
Regards
ispdude
I'm in a bit of a predicament and looking for some help. I'm setting up a Site-to-Site VPN for 7 branches, I have most worked out, but one of the branches is giving me nightmares.
I have head office in Cape Town, ADSL connection. 5 other branches with ADSL connection and one branch with 3G connection (no ADSL available).
I want to install a Cisco ASA-5505 at each site, but I need a public IP on one of the VLANs on each device (i can cope with dynamic as I have a server with a static IP at an 8th branch that won't be part of the VPN, I can set up a DDNS server here - the ASA doesn't support HTTP DDNS services so it would have to be IETF unless there's a company out there that's similar to DynDNS.org but uses IETF protocol, any ideas?). Further I can configure the crypto maps to use hostname lookups.
The problem is that ADSL routers can easily be configured in bridge mode and PPPoE configured on the ASAs, same goes for iBurst, but I've never done this with 3G. That's where I need help, can I get a 3G modem with an ethernet port (instead of the standard PC card or USB) and use PPPoE or some other protocol to bridge it? Otherwise, can I use a 3G router for this and disable the routing? I'm a bit clueless, the ASA-5505 only has Ethernet ports.
As a last resort I can probably use a Cisco 881G, as it can establish a tunnel to a Cisco ASA, but I'd be losing on the security features which I don't want to do.
Regards
ispdude