L2l VPN with public ip of the router and firewall with private IP

Dear all,

I have a requiremnt for site to site VPN configuration but the firewall on the remote end is not obtained public ip, public ip address is termintaed on the router. Please find the attached diagram

LAN--> Firewall - privateip--> router-publicip - ISP

How can I set up the site to site VPN tunnel, enjoy emergency assistance

Thanks in advance...

Mikael

You can configure static NAT for 1:1 for the SAA outside interface with a spare public ip address of the router address.

If you don't have spare public ip address, then you must configure static UDP/500 and UDP/4500 PAT on the router and enable NAT - T on the SAA.

Tags: Cisco Security

Similar Questions

  • VPN site to Site using the router and ASA

    Hello

    I have a Cisco 1812 router that is configured for remote access VPN using IPSec (Cisco VPN Client), my question is if I can configure a Cisco ASA 5505 to connect to the router as a VPN from site to site.

    Thank you

    Karl

    Dear Karl,

    Yor are right, in this case you can create a tunnel vpn site-to-site between devices or you can configure your ASA as hardware VPN client. That is to say; Easy VPN.

    For the same thing, you can consult the document below.

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a00808a61f4.shtml

    Kind regards

    Shijo.

  • VPN client with counterpart on secondary ip address on the public interface of the router

    Hello

    On our office LAN, we have a Linux server than it hosting a VPN connection to a remote client.

    Do this to ISAKMP card on our Cisco router port connections to the internal ip address of the Linux host.

    However, we now want to allow our users to establish VPN connections to our local network using the unit of Cisco VPN Client.

    Of course, this would present challenges, as the ISAKMP our router port is mapped through an internal host.

    So, we tried to set up a secondary ip address on the router and VPN clients to connect to that.

    What we see in our newspapers is as follows:

    Phase 1 is very well established, and the VPN Client prompts the user for a user name and password.

    Authentication of the phase 2 starts, but the router says it's is not to receive a proposal of hash of the client.

    185 12:18:06.943 09/03/11 Sev = Info/4 IKE / 0 x 63000014
    RECEIVING< isakmp="" oak="" info="" *(hash,="" notify:no_proposal_chosen)="" from="">

    (in this case, where x.x.x.x is the secondary ip address on the public interface)

    After that, the Phase 1 SA is removed and the connection fails.

    My understanding is that the Phase 2 negotiation takes place with the ip address assigned to the client in Phase 1, which suggests that the problem occurs because the client communicates with the main on the interface ip address, and no secondary ip address.

    When remove us the mapping of port isakmp and the VPN client to connect to the primary ip address, everything works fine.

    Question:

    It is possible to establish 2 router VPN Client uses a secondary ip address?

    If not, is there some way I can implement the port mapping so that it occurs, the connection comes from a specific ip address?

    Garreth

    Should be supported on IOS.

    The command is crypto ctcp port...

    Check this link:

    http://www.Cisco.com/en/us/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps6659/prod_white_paper0900aecd8061e2b3.html

    Federico.

  • Networking Windows 7 with XP using the router and no internet - machines cannot be

    Hello

    I searched the web and tried all kinds of suggestions to do this, but my new Win7 machine does not always show my daughters XP machine, and vice versa his XP machine is not showing my win7.

    I don't want to have access to the internet so currently have my machine win 7 connected directly to my hub blank so that I can access internet from my win7 machine.  I then another connection from LAN port on my Win7 machine to the router which is also connected his XP machine.

    In my networks and sharing on Win7, I see my homegroup network, which has access to the internet.  Then the other network to the router shows as "unidentified" and the public, but I am unable to change anything on this subject? So can't make a working group or at home.

    The XP machine has also recognized the network and created a shared folder for its own files, but nothing for the win7 machine.

    Both seem to recognize the router and network, but not each other.  Am I missing something?  If it makes any difference, I've already named two machines with the same workgroup name.

    Is anyone able to offer advice?

    Any help is appreciated.

    Thank you

    Vicki

    Hello!

    First you must make sure that the two PC's on the same workgroup. Just checking if they have the same subnet mask. And finally make sure you works discovered the network on Windows 7 PC.

    If computers are subnet masks different IP addresses, they will not be able to see each other.
     
    That I understood your message, you don't want to not PC your daughter to have access to the internet. You can assign static addresses of daughter and your computers. Try to do this:

    1 assign to computer on Win XP LAN network card public static address 10.0.0.10 and the subnet mask 255.255.255.0.  To do this, go in Control Panel > network connections, choose the connection you must edit (the one that goes to the Windows 7 computer) and click Properties. In the windows that opens, double-click Internet Protocol (TCP/IP). Then choose use the following IP address and fill in the fields with the information above.

    2. the PC Windows 7 go Network and Sharing Center > change the settings of the card and double-click adapter that connects the computer to Win XP. Click on Properties and Internet Protocol Version 4. Then choose use the following IP address and put 10.0.0.11 subnet mask 255.255.255.0.

    3. on the Windows 7 PC to go network and sharing Center > advance change sharing settings. In the public profile check turn on network discovery.

    4. make sure that both computers are on the same workgroup (important)

    After completing these steps computers must be able to meet and communicate.
    Hope this will help. Please let me know the results!

  • SSL VPN may be configured on the router from Cisco 881/K9?

    I'm now confused if SSL VPN can be configured on the router from Cisco 881/K9.

    Please someone advise me.

    If Yes, for only 5 users, what I need to buy the license or license is supplied with the router?

    Thank you.

    Yes, and you need a license:

    FL-WEBVPN-10-K9

    License SSL VPN functionality for up to 10 users (incremental), to 12.4 T based only IOS versions

    FL-SSLVPN10-K9

    License SSL VPN functionality for up to 10 users (incremental) for the only based 15.x IOS versions

  • My speed has decreased between the router and the modem is not working properly, what can I do to increase the download speed with my Time Capsule 802.11n

    My speed has decreased between the router and the modem is not working properly, what can I do to increase the download speed with my Time Capsule 802.11n

    A variety of phenomena can affect the performance of its wireless network. You may be able to mitigate some negative effects.

    Solutions to any factors that may have an impact on your wireless network, read use the Diagnostics wireless for you help to solve the problems of Wi-Fi on your Mac - Apple Support.

  • IPSEC with the router and asa 5510

    Hi all

    I have problems connecting ipsec l2l. I have set up a router and asa 5510 make ipsec between them, but it seems to fail on the phase 1. I already check and I am 100% sure that is the key. You can a few shed light on the issue, I have. Here's the output debug I get the two system.

    Thank you

    Hello

    Isakmp policy match on both devices? What version of ios is running on the router and the asa5510

    Thank you

  • Can not connect with the Adobe server to upgrade the PS. Tried with fiervall and the router and called my provider. She is also only CC there are problems!

    Can not connect with the Adobe server to upgrade the PS. Tried with fiervall and the router and called my provider. She is also only CC there are problems!

    Check your hosts file.

    help for that and other adobe.com sure common connection problems read, http://helpx.adobe.com/x-productkb/policy-pricing/activation-network-issues.html

  • Offers day and slow downloads WiFi (very slow).  Is there a way that I can download some updates and new programs using my macbook pro (to a public site in the city) and transfer it on my iMac which is too heavy to cart autour?

    Difficulty to access the updates and downloads with very slow wifi ("country").  Is it possible that I can download some updates and new programs using my MaBbook Pro (retina) on a public site in the city and transfer them on my iMac which is too heavy to cart autour?

    New programs, Yes.

    Updates, depends on what you're updating.

  • your ip address of the router and the printer's address must be the same, so it can print from the computer

    IM setting upward a new router and wants to find the printer but the printer and the router are different VPI address Will this work

    Are they similar addresses, for example 192.168.1.1 for the router and 192.168.1.37 for the printer, it should work file.  If they are more than just a bit different - say for example instead of 192.168.1.37 the printer address is 192.168.0.100 or 169.54.45.21 - then is not likely.  In most home networks, the first three bytes of the IP address must be the same with the fourth byte is different for each computer or device connected to the network.

  • I am unable to connect to my router wirelessly to parents. I tried to reset the modem and the router and it still does not work.

    Presented labtop parents and can connect via ethernet, but still cannot connect to the wireless router. Ive rebooted both the modem and the router and ive also unplugged the power source. Help, please...

    original title: unable to connect to the wireless router?

    Hi Brandon,.

    What operating system do you use? (Windows 7, Vista, XP?)
    You receive any type of error message when you try to connect?
    What exactly happens when you try to connect?
    You receive an internet connection when you connect with an Ethernet cable?
    There are a few good troubleshooting in this thread. I suggest to look to see if it helps at all:
  • The Routing and remote access could not start, error 214500037 (0x80004005)

    My windows server 2003 r2, failed to start the Routing and remote access services. And in the event an observer log, it has error code
    Event ID: 7024, with service specific error 2147500037 (0x80004005)
    I tried to reset tcp/ip and replace ias.mdb and dnary.mdb by a new, but it did not work.

    Thank you

    Hi budhihartono,

    Since you are facing problems with windows server 2003 r2, it would be better suited in the Technet Windows forum. Please post your question in the following TechNet Windows server forum to improve assistance:

    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

  • Can ping the router and the computers to the network, but not beyond router

    I have 2 computers in linux and 3 Windows XP computers.  All can ping the router and inside my network.  Anyone can browse the internet.  None can ping outside my network (google.com or its IP address) if connected directly via the switch or router.  Traceroute shows stopping at the router.  Router firewall is disabled.  Ping on the router tool not working anymore. Linksys WRT54G Router is and I've just updated to firmware 4.21.1 but the old firmware is has never worked. I use 192.168.1.1 for the router.  Linux has some IP fixed all the other usind DHCP.  ISP is a provider of mobile phone to the modem.  Just like cable or DSL, I guess.  I've looked everywhere with no solutions.  Anyone have any ideas?

    Yes, contact your ISP to get it resolved.

  • Unable to connect to the Internet via the router and Modem

    I've recently updated my version of office xp to windows 7. I have a D-link router and a modem with an ISP, and they are all correct, the son. I tried to install the router, but it cannot detect an ethernet cable, even if everything is good. I shot all three offshore, the computer, the modem and router for 60 seconds, reset the router and tried to configure a connection through windows, but nothing seems to work. I have a laptop that can capture the wireless signal and connect to the internet through this. But it's the computer that cannot find the modem or router and does not connect to the internet, I am lost on what to do.

    If your laptop is connected through the router (wireless), then your router is
    more or less OK.
     
    Go to Control Panel/network connections.
    If your PC has both wireless and LAN cards, turn off your PC wireless
    network, here's how:
     
    Right-click on the icon of your PC's wireless network connection. Select Disable. Wait
    until the end of this process.
    Then, right click on icon to connect to the LAN of your PC. Select Disable. Wait
    until the end of this process.
    Now right click on icon to connect to the LAN of your PC. Select Enable. Wait
    until the end of this process.
     
    Open a command window (cmd.exe). We will see if there is a LAN connection. On
    the command line type:
     
    Ping 67.195.160.76
     
    then 'Enter '. What answer did you (paste here). If you receive the answer
    pings, enter this next...
     
    Ping www.yahoo.com
     
    then 'Enter '. What answer did you (paste here). If you receive the answer
    pings, open your browser and go to www.yahoo.com. What is going on?
     
    Other things to check...
    You have DHCP enabled in your router configuration (preferred answer: Yes)
    Set the maximum number of DHCP users to 10 or more (you can reduce that
    later if you prefer).
    Is set to "obtain an IP address automatically" the IP address of your PC
    (preference response: Yes, unless you know what you are doing) or is it
    already a value in place.
     
    "staz2020" wrote in message news: a707c004-e504-4f14-b1d4-2bc465c15eb3...
    > I have recently updated my version of office xp to windows 7. I have a
    > D-link router and have a modem with an ISP, and they are all correct, the
    > son. I tried to install the router, but it cannot detect an ethernet
    > cable, even if everything is good. I have disabled all three, the
    > computer, modem router for 60 seconds, reset the router and tried
    > establishing a connection through windows, but nothing seems to work.
    > I have a laptop that can capture the wireless signal and connect to the
    > internet through this. But it's the computer that cannot find the router or
    > modem and does not connect to the internet, I am lost on what to do.
    >
     
     
  • EIGRP running between the router and ASA by switch

    Hello

    Is that possible I can running an EIGRP between router and ASA by switch?

    Router and ASA connected to the switch with static route.

    Hi Tommy Chin.

    It is possible, we must advertise to the route between the router and ASA.

    Please provide your connectivity diagram to better explain.

    For example...

    interface GigabitEthernet0/0

    Description links to WAN router

    nameif OUTSIDE

    security-level 50

    IP 10.1.1.1 255.255.255.192 ensures 10.1.1.2

    Summary-address eigrp 100 10.1.0.0 255.255.0.0 1

    !

    Confiuration Protocol EIGRP

    standard access list eigrpACL_FR allow a

    !

    Router eigrp 100

    eigrpACL_FR distribute-list in the interface outside

    neighbor 10.1.1.3 OUTSIDE interface

    neighbor 10.1.1.2 OUTSIDE interface

    Network 10.1.1.0 255.255.255.192

    redistribute connected

    redistribute static

    !

    Kind regards

    Srinivas.

    Note: if it solves your problem it mark it as resolved.

Maybe you are looking for

  • Wi - Fi connection problem strange Equium L20 - Atheros AG5005G

    I use ConfigFree - the program will connect to any available network, but can't the system tool (sometimes it does, but only for a while). So it seems I am connected to internet, tools, even if this system shows that I am not (it is displayed in a tr

  • NEITHER USB-6221 SCB-68

    The acquisition of data USB-6221 unit is compatible with the SCB-68? I'm doing a number of analog in action

  • Export the list of files in a folder in the Explorer

    How to export a list of files that that are in an excel file or a text document? Preferably excel. Thank you Tom

  • I get a blue screen with STOP error: 0x0000008e

    Original title: blue screen error I have the blue screen error 0x0000008e (0xc0000005, 0x81e781a7, 0x8c92791c, 0x00000000) on windows vista and I can only boot into safe mode. I don't have the copy of vista because the computer came with it installed

  • Can not activate the silent mode

    Until today, I could turn my z5 and deactivate the silent mode by pressing the volume button. Now when I do that, it changes the volume of media rather than the volume of the phone call. The only way I can turn the mute phone is going through setting