Add the existing network of VPN l2l

I have properly configured VPN l2l between our main site and 2 offices. Now, I would like to allow additional networks on the main site to access the branch sites. Here the doc of Cisco (http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fad90.shtml) presents a method to do this by adding an additional interface. Is it possible to do without the addition of an interface?

Here are the relevant config on the main site ASA (8,0) and one of the remote PIX (7.0):

=========================

ASA (main site)

access extensive list ip 172.16.0.0 outside_1_cryptomap allow 255.255.255.0 172.16.29.0 255.255.255.0

access extensive list ip 172.16.1.0 outside_1_cryptomap allow 255.255.255.0 172.16.29.0 255.255.255.0

card crypto outside_map 1 match address outside_1_cryptomap

card crypto outside_map 1 set 24.97.x.x counterpart

map outside_map 1 set of transformation-ESP-3DES-MD5 crypto

=========================

PIX (remote site)

access extensive list ip 172.16.29.0 outside_cryptomap_20_2 allow 255.255.255.0 172.16.0.0 255.255.255.0

access extensive list ip 172.16.29.0 outside_cryptomap_20_2 allow 255.255.255.0 172.16.1.0 255.255.255.0

card crypto outside_map 20 match address outside_cryptomap_20_2

card crypto outside_map 20 peers set 204.14.x.x

outside_map card crypto 20 the transform-set ESP-3DES-MD5 value

Just add valuable traffic to your access lists. New = 172.16.2.0/24 network

ASA (main site)

outside_1_cryptomap to access extended list ip 172.16.2.0 allow 255.255.255.0 172.16.29.0 255.255.255.0

PIX (remote site)

access extensive list ip 172.16.29.0 outside_cryptomap_20_2 allow 255.255.255.0 172.16.2.0 255.255.255.0

Don't forget your nat exemption acl as well. For example...

ASA (main site)

extended access-list allow ip 172.16.2.0 255.255.255.0 172.16.29.0 255.255.255.0

PIX (remote site)

permit extended access list ip 172.16.29.0 255.255.255.0 172.16.2.0 255.255.255.0

Tags: Cisco Security

Similar Questions

  • Addition of wireless routers in series with the existing network

    I have a client who wants to add at least 3 Wireless throughout their existing network routers. The problem is that these routers must be in the same subnet as the existing network. Oh, we use routers Linksys WRT610N. By default, routers set up a new subnet with a DHCP assigned IP of the primary subnet. I was able to change the static WAN IP, but I do not know how to configure the rest. The point of this is that if a user connected via the ethernet cable or wireless signal, they should be able to access the same network resources. I chatted with support, but they are not allowed to help what it isn't is not a "standard" configuration Anyone can shed some light on this subject? I've done this before with another customer, but its been a few years and it's a different router.

    Thank you!

    You don't want a router. You want a wireless access point. You have wireless routers that you do not use as routers, but only as access points. A router by definition routes traffic between several subnets connected to the various interfaces (LAN and WAN). This kind of configuration is not what the WRT is built for and that's why support said you that it is not a standard configuration for a WRT.

    You can use a WRT as simple access point.

    Reconfigure the router via its web interface. Connect a computer to the router first.

    1. set the LAN IP address on a free IP address in the existing network.
    2. make sure NOT to set a static IP address on the type of internet connection.
    3. on the main configuration page turn off the DHCP server.
    4. now save the settings. You will lose the connection.
    5. unplug the computer and one of the numbered LAN ports of wire to your existing network.

    Now you can access the web interface of the WRT to the new LAN IP address. All wired to the other 3 LAN ports and everything wirelessly connected has access to the network directly.

  • Add the second NETWORK card to vSwitch

    I'm working on trying to add to install a second NIC physical to the vswitch which is installed by default when ESXi. I use the code below, but when I run it, it disconnects in fact the main physical network card and of course, I then lose connection. I tried different varients of this and even finished by adding a port of vmk, which I didn't do. I just want to add the second network card as a standby card network.

    #Add second NIC to the virtual switch
    $nic = Get-VirtualSwitch -VMHost $currentHost -Name "vSwitch0"
    Set-VirtualSwitch -VirtualSwitch $nic -Nic vmnic1
    

    The cmdlet Set-VirtualSwitch accepts a string array as the value of the parameter - Nic. So you should be able to:

    #Add second NIC to the virtual switch
    $nic = Get-VirtualSwitch -VMHost $currentHost -Name "vSwitch0"
    Set-VirtualSwitch -VirtualSwitch $nic -Nic vmnic1,vmnic2
    

    Best regards, Robert

  • Cannot set the Airport Extreme to extend the existing network

    Network WiFi of my holiday home is provided by the router from my ISP (Time Warner). I have an Airport Extreme, which used to be configured to provide the WiFi network to another well, and I would use it to extend the existing on the TWC router network.

    I had a lot of trouble to do a factory reset on the Airport Extreme, but I'm sure I managed (by turning on with the pressed reset button) after several attempts. At least the extreme doesn't show signs of the old network, he has provided.

    When I try to set it up in the Airport utility, he wants only to create a new network. If I click on 'Other Options' and select 'Add to an existing network', the next screen is titled "This Airport Extreme will create a network" and prompts to enter a new network name and password. (Specifying the name of the network current generates an error because the network already exists, as I expect for the creation of a new network.)

    Any ideas on how to tweak this Airport Extreme by extending a network?

    TIA,

    Doug

    P.S. I have reviewed plugging extreme in one of the TWC router EtherNet ports and create its own WiFi network (with the advantage of adding support for 5 GHz), but the last time I tried I lost all connectivity; I'm afraid that the ISP network might protect against too broad network, although the glitch may have been a coincidence. If anyone has experience/ideas on this alternative configuration, I might be willing to try again.

    AirPort Extreme would not be able to connect using a wireless connection and to extend the wireless network of the ISP, but if you can connect the AirPort Extreme to the ISP using a permanent router, wired Ethernet cable, then AirPort Extreme could be used to provide broader coverage of wireless in this way signal.

  • UCS connection to the existing network fabric

    Hello

    I'm trying to get some new equipment:

    2 - chassis with 4 blades of each

    2 6248UP

    1 - C240G - x 2 agile

    2 - 3750 x 10gig expansion.

    Currently, I have 3750's in a battery and intend to add these new 3750's existing battery. Can I connect the 10 g on the 3750 x directly to the fabric of interconnection to bring my new equipment into my existing network?  I thought that this would be considered UCS Uplink Ethernet Ports.

    The reason why I ask, I didn't know that I could not connect servers other than Cisco (IBM with 10 g cards) directly on the fabric and caused my second guess.

    Thank you.

    Hi mjensen

    Fabric interconnection ports are 10 GB interfaces, then Yes, you can connect to the Cisco 3750 Switch via 10Gig ports.   The only thing you want to make sure is that when plug you these devices in transceivers for use based on both ends. If you want to know the list of radios supported on the UCS 6248 take a look at the link below.

    Supported transceivers

    http://www.Cisco.com/c/en/us/TD/docs/unified_computing/UCS/HW/6200-insta...

    You're right about UCSM you want to configure these ports Uplink Ethernet ports!

    Now, the reason why you can not just plug another server ucs to the fabric of interconnection as you IBM server, because the interconnection of fabric does not work like a regular switch.   Only one UCS server can be managed via the GUI UCSM.

    Please let me know if it helps.

  • connect win 7 Home Prem Pavilion to the existing network of 98/xp

    Try adding a Win7 Home Premium 64 HP Pavilion to an existing Win98 and WinXP computer network. He can see the Internet through the router and switches, but not the rest of the network. Is it possible so he could see the local network?

    Hello Win7Newbie.



    Using the features of home Workgroup/group or domain?



    Nice day.

  • Impossible to manually add the wireless network

    I need to manually add a wireless network to the laptop. When I click on add in the wireless connection properties window, however there is no pop-up window. If I try on a similar laptop windows wireless network properties appears. The Wireless Auto-Configuration service is started. How can I get the wireless network properties window?

    I was finally able to solve this problem and I posted the results on another forum, I used for this purpose.  Here is the text exactly as I posted on the other forum.  It answers some of your questions.
    Regarding other software that manages the wireless card, Yes, there are (Atheros), he was not managing the adapter (off a long time ago), however, to be sure, I removed it to run in the registry.

    Here is the text of how I solved the problem, I mentioned.  If you have more questions, feel free to post them.

    *****

    I am just posting this here because I could solve the problem and not able to find a reliable source on the internet on a fix for this and for a problem that is the result of my attempts to fix it.

    This is the situation and my landline.

    I was getting this error message

    "Impossible to migrate dependent packages.

    After trying to install a pacakage KB. It did not matter that one but they have been associated with the Wireless settings.

    I continued to try to install the newer packages.
    KB893357
    KB917021
    KB918997

    Each gave me the same message

    "Impossible to migrate dependent packages.

    I read online that I install KB937143 (update IE7) could help.

    I did this and still got the same message on dependent modules.
    I also had another problem occur.
    In the section my network places properties connection wireless adapters, whenever I clicked the Add button / PROPERTIES without window appears to allow me to change the settings, however, I was able to remove items from the preferred networks window.

    My Automatic Configuration Service wireless is running and took Windows to configure my wireless settings.

    I downloaded the updates for my driver Wlan (WiFiHP 500) and I still had the same problems.

    I restarted KB918997 using the/log option and read the log file. This is the last important lines:

    33.849: MigrateHotfix: hotfix migration KB937143
    34.129: migrating QFE KB937143 with command line: update.exe z q - B: sp2qfe
    36.783: failed 1603 Update.exe.
    36.793: MigrateHotfixes: KB937143 Migration failed
    36.793: DoInstallation: Migration failed
    36.933: failed to migrate dependent packages.
    39.597: message displayed to the user: cannot migrate dependent packages.

    I then uninstalled the KB937143 package and reinstalled KB918997 update with the newspaper of Pétion and he went along. I also tested the buttons add and PROPERTIES in the window of Favorites and those networks worked too.

    I checked the logfile KB918997 and he showed this:
    42.311: MigrateHotfix: hotfix migration KB932168 have
    42.511: migrating QFE KB932168 have with the command line: update.exe z q - B: sp2qfe
    88.768: MigrateHotfix: Hotfix KB932168 successfully migrated
    88.768: MigrateHotfixes: return code: 3010
    88.928: DoInstallation: Migration succeeded

    As a side note, I restarted the laptop frequently just to be sure.

    So, really, the option of running with the Ko log file helped me diagnose the problem.

  • [SOLVED] Cannot add the Vista network printer

    Hello!

    I have a Kyocera FS1118MFP of k-x installed in a XP machine and shared with other computers.

    I installed it successfully in other XP machines, but I'm not able to do so in all Vista machines...

    I already formatted Vista.

    I have the following settings:

    -The discovery of the network: WE

    -Value private network

    -File sharing: WE

    -Public folder sharing: WE

    -Password protected: OFF

    I've run the wizard for XP network enabled file and printer sharing and then restarted.

    I put the same workgroup for Vista and then restarted.

    I don't have any of the following AVs installed:

    I.S. Norton, McAfee, Trend Micro or Kaspersky

    I downloaded the drivers from kyocera and installed on Vista and tried to add the printer again...

    Nothing seems to work. Please help me...

    Already done that it did not work...

    Found another solution but...

    The printer has an ethernet port. Connected that to the router, then install the drivers and successfully detected and installed the printer...

    SOLVED

  • Cannot add the printer network Windows 7 64 bit

    My laptop Home Premium 64 - bit of Windows 7 (client) cannot add the network printer that sits on the Windows 7 Ultimate 64 bit computer. A client XP computer easily added the network printer. When you try to add the network printer, the Windows 7 client searches for the driver on the host computer and says "unable to connect to the printer - the operation has failed with error 0x000003e3. I downloaded the driver from the manufacturer of the printer to the client computer. I also disabled the firewall on the computers... Any help would be appreciated.

    Hello

    ·         What is the number and model of the printer that you are using?

    ·         How many computers are connected to the host computer?

    ·         You are on a domain network?

    Method 1:

    You can check the items below that explain how to install a printer in Windows 7.

    Install a printer

    http://Windows.Microsoft.com/en-us/Windows7/install-a-printer

    Find and install printer drivers

    http://Windows.Microsoft.com/en-us/Windows7/find-and-install-printer-drivers

    Method 2:

    a. now follow the document below to add the printer to the Windows 7 computer.

    http://Windows.Microsoft.com/en-us/Windows7/share-a-printer

    b. If the steps above does not help try the procedure below.

    We need to change the port and check. Let us perform the steps below to install this printer and check.

    a. Click Start, click Control Panel, and double click on devices and printers.

    b. click Add a printer.

    c. Select "add a local printer.

    d. Select "create a new port". Select "Local Port" as the port type.

    e. in the "type a port name" box, type the address in the following format.

    \\[IP address of the host computer]------[the share name of the printer]

    And then click Next.

    f. Select the driver in the list of drivers. If no driver available, click the Windows Update button, wait the process finishes and then search for the driver again.

    g. complete the installation.

    For additional help, refer to the article below.

    Printer in Windows problems

    You can also check out the link below that addresses the same issue when you face:

    http://answers.Microsoft.com/en-us/Windows/Forum/Windows_7-hardware/error-0x000003e3-when-trying-to-install-network/2348b57b-7448-E011-8dfc-68b599b31bf5?msgId=d577ab02-DC48-E011-8dfc-68b599b31bf5

  • How to add the second network card?

    A server (VMware ESX 4.1) works well with a network card. Since I want to add a virtual switch, I need to add another network card. So I inserted into a PCI slot and reboot ESX. But the ESX does not. I need to reinstall ESX to let him find this network adapter?

    Thank you very much for the help.

    The added network adapter is Gigabit PCI Desktop Adapter, D-Link DGE-528 t.

    I tried several model D-link years... None of this can work.

    Use a broadcom or Intel card (and listed in HCL).

    André

  • Call "HostNetworkSystem.UpdateVirtualSwitch" for the error of the object when you attempt to add the second NETWORK card

    Hi there - first post here, so please be nice :-).

    We are just trying to place an ESX4.1 own deployment in our environment (no previous installation of VMWare) to our main office, using Dell M610 and blades blades M600 to what would become our DR - two sites site hosting VMS on Equallogic iSCSI SAN disks.

    I configured 4 of our blade M610 with ESX 4.1 successfully and they work very well.  These blades have double NIC onboard, and after the initial installation of ESX, I could go to the virtual switch and add in the second NIC like vmnic1 (because one had already been detected during installation).  This fine workd for 4 guests on the M610 blades.  However, I came today to make my first installation on one of the old M600 blades and I encountered a problem.

    Installation went without any problems and I was able to add the host in my vCenter.  I can change all the settings without problem (created the Port of VMKernal for my connection to SAN iSCSI etc, but as soon as I try to add in the second NETWORK card, he paused for a while, and then I get the following error message:)

    Call 'HostNetworkSystem.UpdateVirtualSwitch' of object 'networkSystem-56 "on vCenter Server"VCEN01." ournetwork.local"failed. (network name has been changed for post).  When this happens, it locks up again for several seconds, and when the system returns, I can no longer communicate with the ESX host (Observer of events in vCenter watch 'host is not responding' and I find that I can not ping the host unless I reboot it.)

    If anyone has any suggestions I would appreciate it that I don't want to proceed down to the line with our Installer if theres an underlying issue and I need to redo everything.

    Concerning

    EFIN.

    Do you get the same error when you try to add the network adapter by using the command line?

    1. esxcfg-vSwitch - L vmnic1 vSwitch0

    If you have found this or other useful information, please consider awarding points to 'Correct' or 'useful '.

  • Cannot add the secondary network card

    Hello! I bought specially for ESXi (Intel PRO/1000 MT Desktop Adapter, model number 8390MT) a new PCI Intel network card. It is listed as a supported network component. I have pluged it started, the host, went the networking, but I still see only one, the old network card. It would appear there automatically or must something needs to be done in the linux command line? I'm not good with linux, maybe I should just re - install the ESXi?

    Make sure that you add the NIC in the vSwitch. If you just go to the page of networking in the VShpere customer, you won't see the second NIC automatically connected to the vSwitch. Did you do that?

  • Adding two new Windows 7 work stations to the existing network of WinServer 2008

    I bought two new Windows 7 Professional - 64-bit (Dell Precision 3610) workstations. How to set up our server and domain? The server is running Windows Server 2008 R2 Standard. I must go to the permissions on the server to have new stations to be recognized? The new computers are the replacement of the existing jobs and will be connected to the ports of existing data.

    Thank you.

    Hello

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

    TechNet Forum
    http://social.technet.Microsoft.com/search/en-us/Windows?query=server%202008&refinement=1002&beta=0&AC=5

    Hope this information is helpful

  • How to add the WRT54GL network as AP

    I have an existing router with network, all computers have manually assigned IPs. Now, I want to add WRT54GL to serve visitors with the radio. For them to WRT54GL DHCP assign IPs in the range no other computer in LAN uses. I want that they have access to the internet and to the rest of the LAN.

    If I connect WRT54GL by WAN port they only access to internet, but can not see LAN.

    But if I connect via LAN, I can access LAN, but not the internet. It works, if I put the IP of the router (on WRT54GL on 192.168.100.1 but now he is in conflict with the main grave failure of router and network). I do not understand why wireless computers get WRT54GL IP as the gateway and not 192.168.100.1 as it is defined in the basic configuration.

    I guess I should do something in advanced routing, but which?

    You can try tomato or DD-WRT. Tomato, it's a little less 'crowded' that DD - WRT, but you can add options specific to the configuration of DNSMASQ (the DHCP server that works under Linux) that will specify a default gateway.

    If you decide to go to the tomato (which I am more familiar with more of dd - wrt), DNCP/DNS has a box in which you can set options of configuration of DNSMASQ. There is also a link on this page for a site that has great descriptions of DNSMASQ. This site ar options below:

    to set the default 192.168.4.4 route option, do -dhcp-option = 3, 192.168.4.4 or -dhcp-option = option: router, 192.168.4.4

  • To access the branches connected to the main office using VPN L2L by RA VPN

    Hi all

    I am trying to configure access to several remote sites for users that VPN in our main data center.  The data center has a 5520, and branches are connected via L2L IPSec VPN.  All branches have 5505 or 5510.  Remote users use IPSec via the remote Client to Cisco.  In our data center works and L2L VPN remote access are perfect... only now that I need remote users access to branches

    after remote access VPNing (of support), I can't work the part.

    Any help would be appreciated!

    Thank you

    Vpn client access management office subnet via the main ASA site, you must configure the following:

    (1) If you have split tunnel, it must include the branch subnet in the tunnel of split ACL.

    2) allow to "permit same-security-traffic intra-interface" on the main ASA site.

    (3) configure the pool of the vpn client subnet in the lan-to-lan tunnel to the branch.

    On the main site, crypto ACL to one of the branch should say:

    ip licensing

    On the site of the Directorate, crypto ACL to the main site should say:

    ip licensing

    (4) on the site of the Directorate, should also include NAT exemption between the branch subnet to the pool of the vpn subnet.

    (5) after all the changes above, you need to clear the tunnel, so the ipsec lan-to-lan tunnel recover with the new subnet included.

    Hope that helps.

Maybe you are looking for