IPSEC VPN with Cisco ASA

Can Peplink Balance 305 do Site-to-site IPSEC VPN tunnel over the Internet with a Cisco ASA peer Cisco ASA Version 9.1(6)11?

If yes, are there any limitations?

Found that it is possible from the topic below (2 years ago):-

Would need some confirmation on this.

Thanks! Appreciate any help.

We got it working. No issues.

Only thing to note, the ipsec tunnel will not appear in any of the peplink outbound rules setting

U need to set the local ID and remote ID, if the Asa is behind another firewall (ipsec nat issues)

Larry

2 Likes

Great. Good to know.

After establishing the tunnel, is it possible to configure QoS as below and will it work?

QoS > Application > Add > Category “Security/Tunelling, IPSec” > Set Priority “High”

Thanks alot!

Hi

This I did not test. Peplink is mum about this aspect and I cannot get straight answers from support as well.

I am running 5 ipsec link. Peplink to peplink ipsec is more unstable than peplink to cisco and other brands.

U will see a situation where the ipsec link is up and no traffic can get through until you reboot the peplink. Only happen for peplink to peplink

@chesterljs, Qos is not supported in IPSec.

@scl402a, have you further diagnose the unstable issue like perform traceroute to know which hop is dropping the packet? What firmware version you are using for all the Peplink’s IPSec peers?

1 Like

Version 6 works well. Version 7 too unstable

@TK_Liew

As shown in below screenshot, there is an option for IPsec under QoS > Applications. Do you mean this doesn’t work?

Do allow me to further confirm this. Do you mean:

Remote (v6) <—IPSec—> (v6) HQ = Stable

Remote (v6) <—IPSec—> (v7) HQ = Unstable

Remote (v7) <—IPSec—> (v7) HQ = Stable or unstable?

1 Like

This Qos for IPSec is for connectivity below.
<------------------------------------IPSec------------------------------------------>
IPSec peer (Remote) —> Peplink —> Internet <— (HQ) IPSec peer

Not for your case which having connectivity below.
Peplink <—IPSec—> Cisco ASA

Hope this clear your doubts.

1 Like

Ok. Got it.

Thanks.

Hi

Remote v7 to v7 also unstable

All peplink to peplink ipsec unstable when compared to Peplink to CISCO ASA IPSEC

link will show up, but packets not going through until we reboot the peplink (applies for v6 & v7, any combination)

We don’t encounter this issue before. Have you opened ticket on this? If so, please let me the ticket number. Else, please help to open ticket for us to investigate.

Thanks.

1 Like

Hello all,

I hoping this feed will be able to help me out with this issue. I am trying to and not by choice have a Cisco RV320 to Peplink Balance 210 v4 firmware 8.0 via IPsec. I had Cisco help me configure the RV320 since the office just got it they helped out with their hardware setup. Now he and reading states that the EXACT entries need to be in the peplink to talk to one another. I have included Images of both Cisco and Peplink. Can someone help me figure out why it is not working. We are trying to mimic what I love bout the Peplinks since all 3 offices act as if they are all in one location. Using the Peplink VPN AWESOM feature. But my partner did not want to spend on a new Peplink with gig abilities.

Cisco%20SS1 Cisco%20SS2 Cisco%20SS3

Peplink%20Bal%20210%20SS2