Complex network design HELP!

Hello

I am responsible for the implementation of ipsec vpn access to a network with multiple servers, and it is configured as follows:

GW: 172.20.x.1

Device1: 192.168.1.10

DEVICE2: 192.168.1.20

mobile device pool: 10.10.10.0/24

There is a layer 3 switch to which all servers are connected to and which I do not have access.

On this, there are several VLANs and some trunked ports allow traffic above vlan out. I give myself a port on this switch for which I connect to my ASA. I guess it is a trunk port, maybe not.

Technicians remotely need access to this network, mainly devices1 and device2. Also need to access the pool 10.x to test.

My question is, how do I configure my ASA5505 to allow access to these technicians of distance to these devices? This is a whole new ASA5505 out of the box.

Which network set up in the Interior network of the SAA.

I'm confused, please help!

All what you need to do is add these IP addresses and the subnet to the crypto ACL and also make sure that these IPs are part of no. NAT / NAT 0 statement.

If the remote company gave you 3 fps who want access to both devices and mobile IP pool?  If this is the case then your crypto ACL will resemble the following:

VPN - ACL extended permitted ip 192.168.1.10 host access list

VPN - ACL extended permitted ip 192.168.1.20 host access list

VPN - ACL 10.10.10.0 ip extended access list allow 255.255.255.0 host

VPNMAP 5 crypto card matches the address VPN - ACL

access-list no. - NAT allowed extended host ip 192.168.1.10

access-list no. - NAT allowed extended host ip 192.168.1.20

access-list no. - NAT extended ip 10.10.10.0 allow 255.255.255.0 host

NAT (inside) - No. - NAT 0 access list

--

Please do not forget to select a correct answer and rate useful posts

Tags: Cisco Security

Similar Questions

  • Network design help

    Hello

    I have 2 ISPS. I have a VLAN internal on PIX1 unit and use isps1 to get the traffic and our main network is on 10.10.10.x. I plan to build some VPNs to all my customer to ISP2 through another unit PIX2 networks. VPNS are for remote support purposes and to connect the servers to the customer of my position. They will be on different networks other than 10.10.10.x. But I would like to access these servers VPN through my network 10.10.10.x so.

    So I would like to know if it is possible to route traffic PIX1 PIX2 way 10.10.10.x unit can access customer LANs. Please notify

    Thank you

    Well, a really simple solution would involve a router on the 10.10.10.x - router address the subnet IP routing to point to PIX2.

    I assue you have no router, so PIX1 must perform this function.

    Allows to assume that the PIX1 IP address 10.10.10.1 and 10.10.10.2 PIX2.  For the segement LAN the default gateway is PIX1 - so all traffic will be spent in PIX1.  You have static routes for remote VPN subnets pointing PIX2 PIX1.  According to the PIXos version you are running, you must have same-security-traffic permit intra-interface enabled.

    You will perform NAT at one point, 10/8 is fairly common and widespread.

    HTH >

  • HP Network check Helper

    HP Support Assistant indicates that the "Restart required" and also "HP network check Helper' Add - we ask to enable or not enable. What is the help check HP network?

    Hello

    The "HP network control is a complete network diagnostics which can automatically diagnose, fix and easily help you solve the problem that prevents your network or Internet working properly."

    The audit of HP network is part of the HP Support Assistant.  Is the foregoing you are talking about?

    You will find HP network check under the headings of Internet and security in the latest version of HP Support Assistant.

  • What layer are FI in the Cisco hierarchical network design model?

    What layer are FI in the Cisco hierarchical network design model?

    Is this a straigh question? We have a Nexus 7 k for our heart and Port-channel of the FI for them. So for me it layer distribution.

    But when we attach to the NAS. Isilon devices we use between the FI and N7K N3K. This would make the N3K and FI both part of the Distribution layer? Would not be considered layer. However, it does not ACL etc. which usually belong to the Distribution layer.

    I was wondering thoughts people on it. Is the UCS FI and 'One Off' in the model of 3 layer?

    Thank you!

    Craig

    FI can sit to your dist layer. or access.  I've seen deployments where they are deployed at the same time, depending on the size of the cluster of the UCS and band network bandwidth. The distribution layer is usually to be where all the magic of layer 3 arrives (routing, ACL, QoS, FW, application of strategies etc.) and UCS being strictly Layer 2, it could be classified as a device to access-layer.

    Designs are flexible and as long that you consider oversubscription adjusted, you should be fine with the deployment option.

    I hope that others will share their ideas

    Kind regards

    Robert

  • Helps the FS7610 PS Series SAN, 10Gb network design

    Hi, we have currently a square of infrastructure EqualLogic SAN and NAS (2 x PS6510E, FS7500), a stack of two PC8024F 10 GB switches, 2 envelopes chassis m1000e blade with the A1 being a set of switches 1 GB m6220 fabric (fabric A2 a battery of the same thing), the tissue being a pile of m8024k B1 10 GB passes, (fabric B2 a battery of the same thing) and a stack of PC6224 two 1 GB (top of the grid GigE) switches.

    We all have this connected to the 10 GB being its own private network 10.1.0.x SAN network and vlan, nice and isolated from all the rest.  The blades can access the iSCSI shares via their network cards of 10 GB which is all on this network 10.1.0.x.  The NIC 1 GB on the blades are on a public network, and the FS7500 of the customer ports are on this network too via the 6224, so NFS connections are established via the public network to 1 GB.

    We intend to invest in an additional PS Series array to the host to a backup site, for replication.  At the same time, we plan to buy a FS7610 to our main site to take advantage of our 10 GB infrastructure and move the FS7500 existing to our backup site, so we can replicate iSCSI and NAS container volumes.

    That's where we could use some help, because now many things have changed.  Now, the SAN must be on the public network for replication to succeed, AND to take advantage of the connectivity of 10 GB and sharing NFS mount of the FS7610 through 10 Gbit, we need to use network cards 10 Gbit and switches in the network of the client NAS, that are already used for iSCSI traffic (and will in the future be used for connections to SAN vmware hypervisor).  In the FS7610 install and set up the guide, it says

    • Use the switches for network client and for the internal network and the SAN.
    • Use separate subnets for network client and for the internal network and the SAN.

    We can move the SAN and it is a dedicated subnet network and VLAN that is on the public network without problem, but my main concern is to be able to satisfy the recommendations/network configurations required for the FS7610 and avoid the local SAN/NAS traffic through a router to ensure connections of 10 GB.  Advice or tips are appreciated!

    It is the same thing that you are dealing with Linux, but TCP/IP standard routing.   You cannot route private subnets directly on the internet.  We need to create a "Wan".   Do not directly routed on the internet.

    Your WAN will create a private network and a tunnel over the Internet.   OpenVPN is a possible solution.

    A very widespread scenario might be:

    Once you have put WAN in place, on the internet of these routers would be a true internet address (e.g., 62.x.x.x.x) so the two WAN devices can communicate with each other.   They create a VPN tunnel with a new subnet, say 10.3.0.x.

    The WAN router primary side would have a leg on the subnet 10.1.0.x, say with 10.1.0.10 IP address as your default route on the side of EQL SAN 10.1.0.10.

    On the side of the DR this router would have a leg on the 10.2.0.x subnet, say 10.2.0.10.  The default GW on the side DR would be 10.2.0.10.   The router knows how to move packets between networks using the standard range.

    Looks like all you're missing is the "WAN" VPN tunnel between sites.  You want something that will encrypt traffic between the sites anyway.

    Who help me?

    Kind regards

  • Network design... Need help cont.

    I redid this thread in order to give the points. Here's the original:

    http://communities.VMware.com/message/1515861#1515861

    1. vMotion and HA will not work if you have virtual machines stored on the hard disk of the local server. This is why you MUST use a SAN. Centralized storage allows all servers see virtual machines, so being able to move VMs from server to server is possible (iSCSI, NFS, FC, FCoE). If the virtual machines are sitting on the local server, you can not have HA or vMotion.

    2. don't shoot yourself in the foot and try to start production on 2 network cards. You'll end up with people shouting at you on performance. Get a detailed plan and follow it carefully. Get the right equipment and infrastructure in place first or people will not want to embrace virtualization

    Your installation will work? Yes.  It will be the best performance? N ° you need to invest in some more NIC (6 physical NIC in ESX host is a minimum of IMO, I usually go with 10. There you have before, levels of redundancy and less liklihood of the neck of the bottle.

    If you can't do anything else and MUST use 2 network cards, I would honeslty think to keep everything on 1 vSwitch and tagging VLAN to the port of vSphere group layer. In this way, you can use two NICs for all traffic. No best practices.

  • New AD Network Design

    Asked me to design a new network of Active Directory for my business. Where should I start?
    I am looking for a kind of map of Q and A questions about the types of users and of their functions, etc that I can use to make you to configuration etc group.
    Y at - it guides for this kind of thing?

    Hello Mark,

    Your question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please post your question in the following forum:

    http://social.technet.Microsoft.com/forums/en-us/categories/

  • A complex application, need help

    Hi all!
    I'm fairly new to Flex, so please forgive me if my questions may be somewhat silly.
    I am currently evaluating for use as a toolkit user interface (in collaboration with AIR, once it is released for Linux) for an application of Imaging.
    Now, this application is quite complex and I need some answers to some general questions before that I will continue to look into this:
    The app will be rather simillar some animation 3d market applications. You will have several windows that display images (they are quite 'normal' 2d images). These images are generated by an external renderer C++ based. The user interacts with the UI and this will cause information to send the converter, which then creates a new image that will be displayed in the viewport (s). Now to do this, I have of course will have to update the images in the windows dynamically.
    This means if the user interacts, a disclosure of some kinds (I'm not quite sure that is the best way to do this, honestly) will happen in the Flex user interface based on the converter (for example to put the camera here, rotate objects...). Once this is done, the converter produces a new image and it should be updated in the user of Flex interface.
    A question here is speed. The converter will refresh the image up to 25 times / sec, or more if possible and so that should be loaded and displayed in the UI of Flex at roughly the same rate, with as little delay as possible.
    For example the user draggs a slider to the left to rotate the camera to the left. While he does that, the rendering engine gets updated information and spits out pictures that are then updated in windows so that it is always dragging the slider.
    You see my problem here: it must be highly interactive and I can't preload images.
    I tried this place to research on the web and do some research, but I couldn't really find anything like this anywhere.
    So, can someone tell me if this is possible at all, and if so, maybe you can point me in the right direction on reading material. This would be much appreciated.
    I really love Flex for the UI, you can do with it (in my little time to test it, I was able to do some pretty complex UIs without any prior knowledge of the subject). So I would really use it.
    In addition to this, I want the user to be able to draw in the display window on the top of these rendered images. Means of painting of the stuff in there that I will then convert into information for later use. I think I found advice for what is possible, but that's all a bit vague, especially given the context of what's going on with.
    Thanks in advance for any help you can provide. It is much appreciated.
    Skippy

    Gotcha.

    I think that a socket is your best bet, at least for prototyping. We have an alternative: RTMP (real-time message protocol), but it can be more complex for you to implement. But the complexity also gives you flexibility in terms of configuration. For example, RTMP can be used in a situation of tunneling, or even of the HTTP protocol. The socket is a network connection on base and you, end users is not able to use it.

    For the socket, see the documentation for Flex to the flash.net.Socket and search for "socket" in the Flex documentation for information on their use.

    Do the same for RTMP.

  • How can I stop this error arise? "Something seeks to trick firefox by accepting a security update. Your provider network for help.

    Please can someone help I get a message error popup that says "something is to try to trick firefox by accepting a security update. Please contact your network provider and ask for help. "I recently did a clean reinstall and deleted all my program folder before reinstalling a new copy after having a similar King of the error message pop up, but it seems that I swapped some sort of problem for another. I'm a complete novice to computers and any help anyone who is willing to give me must be in the form of step by step and as the possible basis. Thank you.

    Hi lyndystar

    I too had just so sick of this error appeared when your in the middle of something, I ended up having to pay a computer technician to sort on (which I hardly could afford). If all goes well he managed to fix but I will not hold my breath immediately, as usual things go pear for me.
    Sorry I can't be of any use help you as I'm naïve with something like that, that's why I posted the question in the hope that I could fix it myself, but nothing helped.

  • 1500 HP: HP network check Helper - what happens if I do not use Internet Explorer

    This add-on it's an update of Internet Explorer for the detection of problems of internet connection, the tools to resolve these.

    Preferring as I do not use Internet Explorer, Chrome and Firefox, can I guess that I don't need to bother with this?

    Hello @Sail2DeepBlue,

    Welcome to the HP Forums, I hope you enjoy your experience! To help you get the most out of the HP Forums, I would like to draw your attention to the HP Forums Guide first time here? Learn how to publish and more.

    I understand that you have a problem with the help of check HP network and wanted to help you!  I see that you are not using Internet Explorer and I was wondering if there is a need for the program.

    The balance of HP network is part of the HP Support Assistant.  The program is intended for Internet Explorer, so it should not be essential that you install.  I hope this helps.

    Please let me know if this information helps you solve the problem by marking this message as 'accept as Solution', this will help others easily find the information they seek.  In addition, by clicking on the Thumbs up below is a great way to say thank you!

    Have a great day!

  • Load pull to the output corresponding to network design

    Hello

    I tried to design the entrance and exit of the matching networks for a power amplifier using the traction load script and the elements of HBTUNER2. According to the contours of traction load, the optimal point impedance is 15.37 - j21.99 (I chose a compromise between EAP, DCRF and PGain). Now my question is when I use the wizard iMatch to convert this to a 50 ohm termination impedance, use 15.37 - j21.99 or the conjugate 15.37 + j21.99? Otherwise, what is the reason? I always thought that load a script pull gave the impedance looking into the port of the active peripheral side. How did the point impedance suggested by loading a script pull to interpret?

    Thank you much in advance.


  • Network driver help

    Hello

    I just installed windows 7 on my Hp g series and require some network drivers. I read what to do, but I need to short to come on what drivers im. I think I have the appropriate hardware id

    PCI\VEN_10EC & DEV_8176 & SUBSYS_1629103C & REV_01

    PCI\VEN_10EC & DEV_8176 & SUBSYS_1629103C

    PCI\VEN_10EV & DEV_8176 & CC_028000

    PCI\VEN_10EV & DEV_8176 & CC_0280

    is what appears all help would be thank you much

    Kevin

    Hello:

    You need this driver...

    http://h20564.www2.HP.com/hpsc/SWD/public/detail?sp4ts.Oid=5060881&swItemId=ob_105197_1&swEnvOid=4058

  • Try to put in place the PIXMA MX922 on a student network. Help!

    My PIXMA MX922 does not place on my student network. My network is the kind you will first need to get on the student network, then download software so you can connect. I need to print wireless and I can't do and I already have stuff to print. Anyone out there that can help, I appreciate it and get it quick print! I'm on a MacBook Yosemite running.

    Well, I think that after pouring on the manual online I found a solution for wireless printing. Bluetooth. I ordered a dongle used on Amazon for $10 - a Canon suggested, the D - Link DBT - 120 Bluetooth USB Adapter Wireless. There is absolutely no way printers can work on most college networks. The reason being that they are public networks and basically anyone can use the printer from anywhere. Therefore, the only other option is a local printing solution. But instead of a cord that need three people to connect whenever they need to print, optional Bluetooth works great and it is easy to put in place.

  • Internet access only in safe mode with network! Help!

    I can access the internet and open a Web page in SafeMode with network. When I try to open a Web page in normal mode, I can't. I looked at the diagonisic and it says that my firewall or something is not allowed my HTTP port 80 and HTTPS 443 port and port 21 FTP to open or access. I went into my settings of firewall and turned all these, but I have not yet been able to get access to the internet.  HELP PLEASE?

    Hello

    (1) remember you to make changes to the computer before this problem?

    (2) that you get error messages when you access internet in normal mode?

    I suggest you follow these methods and check.

    Method 1: Temporarily disable the security software.

    Note: Antivirus software can help protect your computer against viruses and other security threats. In most cases, you should not disable the antivirus software. If you do not disable temporarily to install other software, you must reactivate as soon as you are finished. If you are connected to the Internet or a network during the time that your antivirus software is disabled, your computer is vulnerable to attacks.

    Method 2: If the method above does not work, you can put the computer in the boot and check.

    How to configure Windows XP to start in a "clean boot" State

    http://support.Microsoft.com/kb/310353

    Note: After completing the steps in the clean boot troubleshooting, follow the section How to configure Windows to use a Normal startup state of the link to return the computer to a Normal startupmode.

    After the clean boot used to resolve the problem, you can follow these steps to configure Windows XP to start normally.

    (a) click Start, run.

    (b) type msconfigand click OK.

    (c) the System Configuration Utility dialog box appears.

    (d) click the general tab, click Normal startup - load all services and device drivers and then click OK.

    (e) when you are prompted, click on restart to restart the computer.

    Thank you

  • Windows Vista cannot find any networks - please help!

    On my laptop Windows Vista comes preinstalled and can have no problem finding networks.

    I also have Ubuntu on my laptop and it is detects networks easily.

    I was told it might be the driver... However, I don't know where to find the latest drivers for Vista.

    Nobody knows exactly where to find them? I am eager to find a simple solution if it is not the drivers.

    I appreciate any help you can give me. There is no sense to me why he does not find networks, including in my house. Thank you!

    Hello

    1. How do you know that the problem is related to the drivers?

    2. you remember to make changes before the hardware or software issue?

    3. What is the brand and model of your system?

    Method 1:

    You can read the following article and try to run the troubleshooter.

    Windows wireless and wired network connection problems
    http://Windows.Microsoft.com/en-us/Windows/help/wired-and-wireless-network-connection-problems-in-Windows

    Method 2:

    We can also refer to the computer or the device manufacturer's Web site and try to install the latest version of the drivers.

    Update drivers: recommended links

    http://Windows.Microsoft.com/en-us/Windows7/update-drivers-recommended-links

Maybe you are looking for