Can I cross two VPN on two interfaces?

Please see the diagram attached pdf.

I can successfully 192.168.60.0 to the DMZ and internal network traffic.

I can pass traffic to DMZ and internal network 192.168.20.0.

Problem I can not pass traffic to a network through two virtual private networks. For example, I can not go 192.168.60.0 to 192.168.20.0, or vice versa.

Any ideas as to why it doesn't work?

Thanks in advance.

I was wondering if the router 1751 both pix 501 No. - nat and crypto ACLs include the other subnet. In addition, on the pix 515, two subnets should be included for the two lan - lan vpn.

for example

on router 1751.

access-list no_nat 192.168.20.0 0.0.0.255 172.24.0.0 0.0.0.255

access-list no_nat 192.168.20.0 0.0.0.255 192.168.1.0 0.0.0.255

access-list no_nat 192.168.20.0 0.0.0.255 192.168.60.0 0.0.0.255

access-list lan2lan 192.168.20.0 0.0.0.255 172.24.0.0 0.0.0.255

access-list lan2lan 192.168.20.0 0.0.0.255 192.168.1.0 0.0.0.255

access-list lan2lan 192.168.20.0 0.0.0.255 192.168.60.0 0.0.0.255

on pix 501.

access-list no_nat 192.168.60.0 255.255.255.0 172.24.0.0 255.255.255.0

access-list no_nat 192.168.60.0 255.255.255.0 192.168.1.0 255.255.255.0

access-list no_nat 192.168.60.0 255.255.255.0 192.168.20.0 255.255.255.0

access-list lan2lan 192.168.60.0 255.255.255.0 172.24.0.0 255.255.255.0

access-list lan2lan 192.168.60.0 255.255.255.0 192.168.1.0 255.255.255.0

access-list lan2lan 192.168.60.0 255.255.255.0 192.168.20.0 255.255.255.0

for pix 515.

access-list allowed vpn1_1751 172.24.0.0 255.255.255.0 192.168.20.0 255.255.255.0

vpn1_1751 list of permitted access 192.168.1.0 255.255.255.0 192.168.20.0 255.255.255.0

access-list allowed vpn1_1751 192.168.60.0 255.255.255.0 192.168.20.0 255.255.255.0

access-list allowed vpn2_501 172.24.0.0 255.255.255.0 192.168.60.0 255.255.255.0

vpn2_501 list of permitted access 192.168.1.0 255.255.255.0 192.168.60.0 255.255.255.0

vpn2_501 list of permitted access 192.168.20.0 255.255.255.0 192.168.60.0 255.255.255.0

the only bit I don't know is the No. - nat on pix 515. I guess we should give it a go first, then find the No. - nat troubleshooting.

Tags: Cisco Security

Similar Questions

  • Two interfaces WAN ISP in the same network

    Hello world

    I am faced with a really simple but delicate scenario. My ISP gives me IP addresses public 2, both in the same network. They also gave me the default gateway which is of course in the same network too.

    I need two fully operational ip addresses, but I realized that I can't have two interfaces (routed interfaces) in the same network segment. I have just a single router (Cisco 2911). A friend told me that I might be able to set this up using VRF, but as far as I have read, there is no way to use VRF to achieve this.

    Is it possible to use two (or more) ip addresses to redirect traffic to the same default gateway in the same router?

    Thank you!

    Miguel

    Hi Miguel,.

    If you want just your 2911 have set up two public IP addresses, you can set one of them as secondary IP address. Suppose that 192.0.2.1/29 is your default gateway, and 192.0.2.2/29 and 192.0.2.3/29 are your IP addresses. So to have both configured, you'd:

    interface Gigabit0/0/0 ip address 192.0.2.2 255.255.255.248 ip address 192.0.2.3 255.255.255.248 secondary
    And voila - that should do the trick :) Best regards, Peter
  • Can I use two vpn set in my iPhone?

    Can I use two vpn set in my iPhone?

    Yes, you can use but not at the same time. You can add more than one vpn on your iPhone but can only use one at a time. Another way to use the two VPN at the same time, is that you can have an extra router to connect the two VPN at the same time. For more information on this, you can take a look at these answers https://www.quora.com/Why-cant-I-use-two-VPN-at-the-same-time hope this will solve your problem to his subject.

  • This allows traffic between two interfaces ethernet on a PIX

    I have a PIX with interface inside, IP 10.198.16.1. It also has an interface called WTS, IP 10.12.60.1. I'm having difficulty to allow traffic from the 10.198.16.0 network to cross the PIX in 10.12.60.0. I'm trying specifically to allow access to a server with an IP address of 10.12.60.2.

    I enclose my config. Any help would be greatly appreciated!

    OK, so the inside interface has a security level of 100, WTS has a security level of 75, so traffic from inside to WTS is considered outbound traffic, which is allowed by default. All you need is a pair of nat/global (or static) between both interfaces so that the PIX knows how NAT traffic between two interfaces (remember, the PIX do NAT).

    You have this in your config file:

    NAT (inside) 1 10.0.0.0 255.0.0.0 0 0

    who says all traffic inside, interface with the IP 10.x.x.x address will be NAT would have, but you must then a global for the interface WTS define what those IPS will be NAT would.

    Adding:

    Global (WTS) 1 interface

    will be PAT all inside resolves the IP address of the interface WTS and allow traffic to flow between the interfaces. If you prefer the hosts inside the interface to appear as their own IP address on the WTS network, then you can use a static command and NAT addresses themselves, actually doing NAT, but not actually change addresses:

    static (inside, WTS) 10.198.16.1 10.198.16.1 netmask 255.255.240.0

    Hope that helps.

  • Can I connect two computers with media center

    I have two laptops running windows 7 and an xbox 360. I tried to connect the two to the 360 to watch the videos stored on the two but unfortunately I found, I can connect only one at a time, I'm now trying to see if I can connect the two laptops with media center and access to both of my xbox using the an already established connection. Can anyone help?

    one at a time and connect a second pc, you must remove the
    WMC Extender and remove the pc to the Xbox interface association.
     
     
    Barb
     
     
     
     
    Please mark as answer if that answers your question
     
     
     
     
  • How can there be two accounts in the same user name

    How can I have two usernames even, that of the Australia and the other in the United States?

    Hello

    Thanks for posting your query in Microsoft Community.

    a. are both connected anyway through the network (for example in a server domain common network, VPN etc.)?

    b. What is a local user account or an Microsoft account?

    Unless the systems in the two countries are connected via a common domain, they are independent and can have accounts of local users with common names. If you talk about Microsoft accounts, then they can be configured two different computers, but the information that is on the server online sync is common to both systems.

    Additional information:

    User accounts: FAQ

    Hope this information is useful. Let us know if you need more help, we will be happy to help you.

  • How can I Cancel two step for my email account security code?

    How can I Cancel two step for my email account security code?

    Now, to see if you can always reactivate this account, the only thing you can do is:

    • Go to Hotmail and try to connect with it.

    • If you can, then you have this back.

    That's how Hotmail determines if or not someone really changes their minds when they disabled or abandoned an account. All you really need to do is log in there, using the web interface, and if she comes back, fantastic.

    If the connection fails

    If you cannot (in other words, if the connection fails), this means that one of two things:

    • One, the account itself is really deleted - and there is no e-mail address of the same name

    • Or it means that the e-mail address was finally released, so that it can be reused by other people and someone else took.

    Now, the only way to determine whether or not this is the case is here:

    • Try and create a new Hotmail account with the old email address. If it works, you're back in business.

    • If it fails, I don't know how to get this email address.

    As I said, it could very well have been reassigned to someone new who came and chose as their new email address on Hotmail.

    ----

    However, you can try to talk to Microsoft about this page: support.microsoft.com/contactus

    Choose the 'Chat now for general information", enter your name and choose the option"Hotmail"for the reason.

  • can perform us two actions with a single button in two clicks, one after the other?

    Mr President.

    can perform us two actions with a single button in two clicks, one after the other?

    I want that when I click on the button Add once it add data to the database and when I click again on this button it clears the form data to the empty fields.

    Concerning

    Tanvir

    In the code, it should be easy.

    The following code adds that a button called butman with text 'ADD '.
    It then registers a listener that will be called if the user clicks the button.

    This listener then calls the runAddData method if you clicked butman while it contained the text of "ADD" and it calls the runClearData method otherwise.
    That's why he will swap the functionality of the button between ADD and CLEAR on each click.

    final Button butman = new Button("ADD");
    butman.setOnAction(new EventHandler() {
              @Override
              public void handle(ActionEvent t) {
                        if (butman.getText().equals("ADD")) {
                                  butman.setText("CLEAR");
                                  runAddData();
                        } else {
                                  butman.setText("ADD");
                                  runClearData();
                        } // END IF-THEN
              }});
    

    I hope that's what you wanted.

    Further reflection.
    You might want to run the ADD and CLEAR methods in their own son so that it can run in the background without slowing down your user interface.

    I also reuse rather a single button for several features instead of to apply with hundreds of nodes used only rarely with masses of code to show and hide as needed.

  • can I save two devices on a single iCloud?

    can I save two devices on a single iCloud?

    Yes, if they use the same account Apple ID (iCloud).

    http://www.Apple.com/icloud/Setup/

  • How can I multiply two matrices together in number?

    How can I multiply two matrices together in number?

    Well, there is a function in numbers call sumproduct() that can help you.  Post a screenshot of what you will help us to better help you.

    real matrix operations are not supported in number.

  • can I have two apple on a single device ID

    can I have two apple on a single device ID

    Hi, no you can use only a single iD associated with a single device.

  • Why Apple can't do two systems? First of all, we are protected, and the other is free just like android, but in the style of the iOS and Apple needs a request so we can manage and see new products from an application and do not go on this site!

    Why Apple can't do two systems? First of all, we are protected, and the other is free just like android, but in the style of the iOS and Apple needs a request so we can manage and see new products from an application and do not go on this site!

    and I don't know that if Apple make a system more freely, there no need for any device on Earth but iPhone.

    http://www.Apple.com/feedback/

  • How can I sync two phones with my computer?

    I have two phones S3, one is mine and the other my husband.
    Can I sync two phones to our computer at home?
    If so, how?

    Hi there, have a look

  • Can you connect two cable on wifi networks?

    Basically, I'm trying to build it.  It was much easier in photoshop than to the fact of installation.

    There are many features, some wired, some wireless.  I ran son where I can run threads, but it's a bit more difficult that I thought for a domain.

    Basically, I need to connect two wired over wifi networks.   The 2nd must share this wifi via ethernet. (I can exchange picture 2 and 3 if necessary)

    There are also two 4-port switches in the mix for the NAS in the basement and other devices connected.

    Everything works the latest firmware. All computers on the network are running 10.11.4 Mac

    Can you connect two cable on WiFi networks?

    In theory, Yes.  In practice, not if you work with image, video files or other media.

    Honestly, it's a big House of cards, and even if it does not, it will be very SLOW... Since everything will depend on a connection without wire between Imagine and Imagine 3... and wireless will be much less bandwidth of a wired connection, not to mention the much less reliable than a wired connection being.

    If unfortunately, the bottom line here is that a professional, or even a good amateur would never has something like this.

    There are some other questions to ask, but by far the most important would be... is it possible that Imagine and imagine 3A connect using a wired Ethernet cable connection?

  • How can I have two buttons for 'new tab' in version 4?

    In version 3.x, there is a removable button on the toolbar for 'new tab' plus a button '+' at the end of the address of the open tab I could click to create a new tab.
    In version 4, I can have the removable button, but I do not see how to add the button at the end of the address of the open tab. I can move the single button at the end of the address window, but I can't have two buttons.
    Is it still possible?

    You must drag the button new tab (+) of the tabs to another toolbar toolbar to make the second button to appear.

    "Firefox > Options > toolbars" or "view > toolbars > customize.

Maybe you are looking for

  • drive time capsule is not available

    The time capsule disk is not available. Finally, he worked on 08/08/2016.

  • Update Apple software for iTunes, update

    Today on my Windows 7 64 - Bit, Apple Software Update detected an update for iTunes; but it would not be installed without error.  Not able to reproduce the error code, I believe that the error was on the download.  Finally, I installed the updated v

  • The contact in my iPhone didn't appear on the iPad with facetime

    MY sister has a new iPad. Its coordinates are in my iPhone with FaceTime listed, but not in my iPad. How can I fix this please?

  • Charging without a computer

    Hello I use the Clip 2 GB and I have a USB (something like that). However, the Sansa Clip does not charge when I plug it into the usb charger. It seems that she required only when connected to a computer. Is this a known issue? Can I fix this problem

  • Question about the program clearing browser history

    Aftre the class implementation and the instructions to import appropriate, I can access URL in an application using these instructions: {Private site = Browser.getDefaultSession ();site.displayPage ("http://www.whatever.com"); Is not indicated some m