Client needs to access the devices on the existing site to site tunnels

Hello and thanks in advance.

We use ASA5510 in respect to the vpn appliance and currently have 90 + vpn tunnels (site to site tunnels) ipsec connected to this ASA.

Recently, we configure a tunnel for one of our customers (site in tunnel).

Now, this client must have access at least 10 existing tunnels a site that I have.

They must be able to access the devices on this segment.

How should I proceed with this application?

Can I update all existing tunnels site at 10 to add this range of ip addresses of places (clients)?

Yes, you need to add this new subnet as interesting traffic on all 10 tunnels (on card crypto ACL) If you need two-way communication.

Kind regards

Averroès.

Tags: Cisco Security

Similar Questions

  • What files are needed to access the aspect of the heritage of GarageBand?

    What files are needed to access the aspect of the heritage of GarageBand? After the upgrade my MacBook Pro and Mac Pro, the appearance of the inheritance is only accessible to the general public on the MacBook Pro. What files are needed for these instruments of the legacy and the filters on my MacPro? I read that the removal and reinstallation of GarageBand 6.05 will do but 6.05 GB certificates have expired and is no longer allow it to be installed. Any help is greatly appreciated.

    I read that the removal and reinstallation of GarageBand 6.05 will do but 6.05 GB certificates have expired and is no longer allow it to be installed. Any help is greatly appreciated.

    You always have an installer for GarageBand 11?  An installation of iLife 11 DVD or the DVD Installer original system for snowLeopard with applications for funding?

    You can install GarageBand 11 of these media, if you set the date system your mac to a date until the installer has been released. Then, the certificate will be valid.

    the appearance of the inheritance is only accessible to the general public on the MacBook Pro.

    But because of legacy patches are available on your MacBook pro, you can copy all the missing files from the library of the Instrument and loop library in your other Mac.

    Compare these files in the folder/library on your system drive on Mac of high level.

    The instrument library: Library/Library/Application Support/GarageBand/Instrument.

    and loop library: / Library/Audio/Apple Loops/Apple /.

    Copy all the files to the corresponding folders on your MacBook Pro that is not there.

  • I've set up another configuration of TCP/IP, but it does not connect. I need to access the 3 different machine networks. Any ideas?

    I've set up another configuration of TCP/IP, but it does not connect. I need to access the 3 different machine networks. Any ideas?

    original title: alternate tcp/ip

    If by "alternate TCP/IP configuration" you mean the settings on this screen--> http://tinyurl.com/42kbqqz, then, to quote Inigo Montoya, "you keep using that Word. I don't think it means what you think it means. »

    The 'alternative' configuration settings tab, if you select "IP address private auto" (APIPA) or "specified user" is only used IF "obtain an IP address automatically" is set on the tab 'General' (http://tinyurl.com/8p9hn) AND the adapter cannot get an IP from a DHCP server.

    Most cable networks use a DHCP server to automatically assign IP addresses.  In this case, just plug your Ethernet cable and you're automatically configured and connected.

    If the problem is that your network requires a static IP address (that is, they use a DHCP server to automatically assign IP addresses), you will need a third-party network settings manager.  If you have an IBM (Lenovo) ThinkPad, you can use "Dial-up connections." IBM Otherwise, see this Google search (I have no experience with any of the applications shown, so I can't comment about them): http://www.google.com/#sclient=psy&hl=en&source=hp&q=network+configuration+switcher&pbx=1&oq=network+configuration+switcher&aq=f&aqi=g-v5&aql=&gs_sm=e&gs_upl=23l1333l1l1599l12l8l0l0l0l5l278l1344l0.7.1l8l0&bav=on.2,or.r_gc.r_pw.&fp=74e371c96a48f4b&biw=1024&bih=649

  • internal hosts cannot access the internet w / L2L configured tunnel

    The internal hosts behind the ASA cannot access the internet with a configured tunnel to L2L. The L2L tunnel is mounted and passing traffic correctly. However, the internal host cannot access the internet through the ASA. I think I have my NAT watered somewhere. I can't even a host statically mapped to the internet. It might be because I'm used to having a WAN IP to the external interface which differs by the CIDR block assigned by the ISP. In this case, it's all together, with the ASA outside interface occupying the first available address.

    We have been assigned a CIDR range x.x.x.64/28. x.x.x.65 is my front door and my first usable est.68, by the PSI (I guess what they utilisent.66 et.67 for internal use). External interface of the ASA est.68 and I'm trying to get NAT others. I'm Polo all DHCP clients internal and have some static entries as well. Below is the relevant NAT config. Yet once, all traffic passes above the tunnel properly, but not from inside to outside. If more information is needed, please advise.

    interface outside

    IP address x.x.x.68 255.255.255.240

    NAT-control

    Global x.x.x.69 - x.x.x.77 2 (outdoor)

    Global 1 x.x.x.78 (outside)

    NAT (inside) 0 access-list sheep

    NAT (inside) 1 10.10.10.0 255.255.255.0

    public static x.x.x.69 (inside, outside) STATIC_NAT_EXAMPLE netmask 255.255.255.255

    internal access-group interface inside

    Route outside 0.0.0.0 0.0.0.0 x.x.x.65 1

    internal to the 10.10.10.0 ip access list allow 255.255.255.0 any

    ! Remote LAN is 192.168.10.0/24

    access-list sheep extended ip 10.10.10.0 allow 255.255.255.0 192.168.10.0 255.255.255.0

    Can you post a "show sysopt run?

    Try this command to enable proxy arp.

    No outside sysopt noproxyarp

  • I need to edit the existing customer's site, I only have their login information and new photos.

    I need to edit the existing customer's site, I only have their login information and new photos. I can't change it with the editor in the browser as it was exported by using an older version of muse and I have not all the other files of the Web site. Help, please.

    In this case, you will need to ask the client to share the muse file and have the same updated file, and then publish on the customer site. When you are added as an administrator, you will see the option site > site list.

  • Just recently, I receive the following error message when you try to access the web sites. I get a pop-up window indicating "Exc in ev handl: TypeError: c.location is null" then I have to click ok. There is a problem with some plugin?

    Just recently, I receive the following error message when you try to access the web sites. I use Firefox browser version 10.0.2. I get a pop-up window indicating "Exc in ev handl: TypeError: c.location is null" as the web site page is displayed in the browser winder. So, I have to click ok. Any link/website I go to what happens. There is a problem with some plugin?

    It is only a problem for the SiteAdvisor users who are still on 3.4. This problem is resolved in the latest version of SiteAdvisor, which is 3.4.1.195. Go to http://siteadvisor.com and click on download. This will fix the problem.

    Meanwhile, SiteAdvisor team will push down a JS update in the coming days 1-2 to automatically resolve this problem in version 3.4.

  • Since the installation of the last update of iOS on my iPad I'm unable to type in the address bar of safari. I can access the Web sites of my favorites, but when I try to enter a new address safari closes its doors.

    Since the installation of the latest update on my iPad, I'm unable to type a new address in the address bar of Safari. I can access the Web sites of my favorites, but when I press the address bar Safari closes its doors.

    I reset holding home and power button at the same time. I did that 4 times. I also left all the settings.

    I am also unable to access the server from imessage. I don't know if these two things are related, but the two that happened after the update to iOS 9.2.1

    Since this announcement, I found a Reddit thread that suggests a temporary solution by disabling Safari suggestions. It worked for me.

  • Any time I try to access the web site GOOGLE, this message 404 not found (nginx)

    Any time I try to access the web site GOOGLE, this message appears.

    Any suggestions as to what is the cause and what is the fix.

    Thank you

    Hi LindaPhillion,

    1. Did you the latest changes on the computer?
    2. What web browser do you use?
    3. Are you having similar issue with any other search engine?

    You will usually receive this error when Internet Explorer is able to connect to the website, but the webpage cannot be found. This error is sometimes caused because the webpage is temporarily unavailable or that the Web page has been removed.

    Get help with the Web site (HTTP error) error messages.

    http://Windows.Microsoft.com/en-us/Windows-Vista/get-help-with-website-error-messages-HTTP-errors

    Note: Above article also applies to Windows XP.

    Note: Try the step only if you are using the web browser Internet explorer below.

    Refer to the article below and try the steps mentioned, check if it helps.

    How to optimize Internet Explorer

    http://support.Microsoft.com/kb/936213/ro

  • How to change the page numbers after adding & save page numbers in the pdf document - need to change the existing page printed on the upper right in the header numbers

    How to change the page numbers after you add and save the page numbers in the pdf document - need to change the existing page printed on the upper right in the header numbers.

    These page numbers were initially created using Acrobat PDF header and footer.

    I have a 750 page pdf document that I've created.

    I have to sometimes the pages up and down after that I added the page numbers in the document by using the Header_Footer tool on the right column of tools.

    But after you save the document, if I get a few pages around, I can't go back and change the page numbers.

    I thought that the page numbers, as indicated in the header and footer must have changed automatically, but I guess that once its print, that it cannot be edited - is that, as what is?

    So I guess we should always first get a copy without numbers of pages before confirming the documents and the creation of an index.

    A way to remove these page numbers already there and add new page numbers.

    Its a lot of work to align 750 court documents and then realize that you must move some and then realize the page numbers cannot be changed and thus begin to do this all over again to compile which can take about 10 hours.

    My question is quite simple, but I hope that overall, I got my point. Sorry if I made it is too complex.

    If no simple way, want to know if anyone has another different tool or a few recommendations to better highlight what I'm doing wrong.

    Thank you for your review and response.

    You should be able to update with tools - Pages - header & foot-

    Update... It not work for you?

    If this isn't the case, then try to remove from this menu and then re - adding them.

    Tuesday, June 23, 2015 23:55, Fortune Mile [email protected]>

  • Add JS dropdown to the existing site?

    Hello

    The image below is a site that was designed by another company.  The owner wants me to start doing updates for her, and one thing he would like to is to add some kind of drop-down list in the main navigation elements (seen in green circle).

    Anyone have any ideas or suggestions on how I can do this in JS without messing up the design of the existing site?  One thing I don't like is that if you add the drop-down list, it kind of covers the large photos as if he dropped down this will cover this girl's face.  All the suggested ideas.

    Thanks, Guy deaf

    headers.jpg

    Certainly do in CSS.  It is already half started for you.  If you want a drop-down list there are a few things to keep in mind.  The top level of a menu drop-down should not go anywhere or go to an empty anchor tag "#".  Then, create your drop-down menu in the structure of the ul as:

    • toplevel
      • toplevel-sub-element
      • Sub item2

    This is a very simplistic example.  Then do you things in css like:

    UL ul {opacity: 0; visibility: hidden ;}}

    Li: hover > ul {opacity: 1; visibility: visible ;}}

    Once again, very simplistic.  Depending on the size of the text, I almost consider however a more sensitive menu design because this text is very small for click mobile.

  • A VPN client / ASA cannot access the Internet.

    VPN clients can get to the servers internal/DMZ but not Internet. This is the partial config of the SAA. TIA

    Pool VPN 10.17.70.0

    DMZ 192.168.100.0

    172.0.0.0 internal

    -------------------------------------

    nonatdmz list of allowed ip extended access any 192.168.100.0 255.255.255.0

    access extensive list ip 172.0.0.0 nonatdmz allow 255.0.0.0 10.17.70.0 255.255.255.0

    standard access list splittunnel allow 172.0.0.0 255.0.0.0

    Global interface (10 outside)

    Global interface (Businesspartner) 10

    NAT (inside) 0-list of access nonatdmz

    NAT (Inside) 10 0.0.0.0 0.0.0.0

    NAT (DMZ) 10 0.0.0.0 0.0.0.0

    Vinnie, happy that you have found here.

    Telnet for asa by vpn session, you need to add this statement.

    management-access inside

    In this same connection see split tunnel vs local Allow only lan access, you can learn the differences and you will better understand your configuration asa related to ra vpn.

    http://www.Cisco.com/en/us/products/ps6120/products_configuration_example09186a0080702999.shtml

  • Client VPN cannot access the different internal subnet

    Hi all

    I use pix 7.0 and 4,8 vpn client

    When I connect with the vpn client, I see the subnet behind the pix (10.61.1.0)

    However, there is a router on that subnet that connects to two other sites (10.61.2.0 and 10.72.2.0)

    I can ping from the pix to these subnets command line.

    When I connect using the vpn client I only see the subnet behind the pix and not the other two subnets?

    I have a command-line 10.0.0.0 255.0.0.0 10.61.1.250 (the ip address of the router) on the pix, but this doesn't seem to help?

    The response from the ping is request timed out one or the other subnets.

    Any suggestions on what route, I need to add or is there an ACL to be added?

    Current and ACL routes is:

    0.0.0.0 0.0.0. The ISP router address

    10.0.0.0 255.0.0.0 10.61.1.250

    Outside_access_in list extended access permit icmp any one

    access extensive list ip 10.61.1.0 inside_nat0 allow 255.255.255.0 10.61.1.224 255.255.255.240

    NAT (inside) 0-list of access inside_nat0

    NAT (inside) 10 0.0.0.0 0.0.0.0

    Access-group Outside_access_in in interface outside

    All responses appreciated.

    first of all and above all, the pool of the vpn client should not overlap with the asa inside the subnet, or any connected subnet.

    <-->Asa <-->(10.61.1.250) Internet router <-->10.61.2.0 and 10.72.2.0

    allow inside_nat0 to access extended list ip 10.61.1.0 255.255.255.0

    allow inside_nat0 to access extended list ip 10.61.2.0 255.255.255.0

    allow inside_nat0 to access extended list ip 10.72.2.0 255.255.255.0

    Allow Outside_cryptomap_dyn_20 to access extended list ip 10.61.1.0 255.255.255.0

    Allow Outside_cryptomap_dyn_20 to access extended list ip 10.61.2.0 255.255.255.0

    Allow Outside_cryptomap_dyn_20 to access extended list ip 10.72.2.0 255.255.255.0

    In addition, a static route must be configured on the 10.61.1.250 router:

    IP route

  • Need to access the BIOS screens

    "HP Pavilion p7-1447 c desktop PC Win8x64.  FN2 gives me the diagnosis UEFI screens.  I need to enter the BIOS to set the NumLock on at all times.  How to access the BIOS screen?

    Hello

    Turn on and immediately press the ESC key to access the select start--> F10 menu to access the BIOS.

    Best regards

    ERICO

  • I need to access the e-mail account of my dead son, the account is locked and I don't know the password, nor answers to security questions... Help!

    My son's e-mail address is * address email is removed from the privacy * I tried to reset the password, but the account is locked... apparently, someone else tried to access his account.  My address is * address email is removed from the privacy *.  I have a death certificate, his date of birth and place of birth, but cannot go further.  I need to access his account to clear and close.  In addition, need access to his FaceBook page that requires the use of its email account...  He died last December, and people still hold on him through these 2 avenues... just want to get them closed.  I spoke with Windows Live and also Microsoft support and they just pass me to other phone numbers that don't work or back to Windows Live internet support... go into vicious circles now and don't get no where...

    Please help me!

    Rodney Voris

    While your application may very well be authentic, it could also be interpreted as a surreptitious attempt to bypass security.

    It is in the terms of use and the Code of conduct of the responses of these forums to request or provide assistance to the cracking a password. Do not forget that you agreed to these and review if necessary.

    You can view the policy of Microsoft about lost or forgotten passwords (KB189126) for more information on what resources are available to you.

    The only advice I can offer you is to use the computer of your son end access to e-mail and social networking areas. The passwords can be recalled on the computer account.

    With all that said, you have my deepest condolences for your loss.

  • Need to access the 'Documents and Settings' folder in Windows 7

    I am importing an ArcMAP GIS project to my new Windows 7 computer (the project was launched on Windows XP).  Because the files in this project were initially located in the subdirectories of the "Documents and Settings" folder, map search these files in this folder.  So, I need to access this folder if I put the files in the location that arcmap is expected to make them, or that I inform manually map the new location, one at a time, hundreds and hundreds of files.  Is there a way I can access the "Documents and Settings" folder to add new subdirectories and files in it?  After some research, I found the folder, but I said that I don't have authority (even as an administrator) to access and modify the content of the folder.  Thank you

    I am importing an ArcMAP GIS project to my new Windows 7 computer (the project was launched on Windows XP).  Because the files in this project were initially located in the subdirectories of the "Documents and Settings" folder, map search these files in this folder.  So, I need to access this folder if I put the files in the location that arcmap is expected to make them, or that I inform manually map the new location, one at a time, hundreds and hundreds of files.  Is there a way I can access the "Documents and Settings" folder to add new subdirectories and files in it?  After some research, I found the folder, but I said that I don't have authority (even as an administrator) to access and modify the content of the folder.  Thank you

    Hey ITromble

    read the below information about junction points even through it was written on vista

    http://www.Svrops.com/Svrops/articles/jpoints.htm

    Old path

    New path

    \Documents and Settings

    \Users

    Here is the vista forums

    link below is in Forum windows 7

    http://answers.Microsoft.com/en-us/Windows/default.aspx#tab=2

    Walter, the time zone traveller

Maybe you are looking for