PIX501 (sites) - 3005Concentrator (HQ) any2any connection

Hello

We use PIX501 on our sites to connect via VPN to PIX515 headquarters. We also have a concentrator 3005. Here my question. Is it possible to work as a VPN concentrator using the hub instead of the PIX515 for linking sites together?

Thank you

Yes, the 3005 will be capable of acting as a hub for traffic has spoke-to-spoke, unlike the PIX you've probably discovered. You just need to make sure that your list of network LAN-to-LAN on the 3005 (and each ray 501) includes the traffic for all the other rays.

If each ray is a subnet of 10.x.x.x say, so it's fairly easy. Let's say spoke1 is 10.1.1.0/24, spoke2 is 10.2.2.0/24 and so on. On each 501 your ACL crypto has to say:

Spoke1:

license of crypto list to access ip 10.1.1.0 255.255.255.0 10.0.0.0 255.0.0.0

Spoke2:

license of crypto list to access ip 10.2.2.0 255.255.255.0 10.0.0.0 255.0.0.0

and your LAN-to-LAN configuration on the 3005 for each ray says otherwise:

To Spoke1:

Network Room 10.0.0.0/0.255.255.255

10.1.1.0/0.0.0.255 remote network

To Spoke2:

Network Room 10.0.0.0/0.255.255.255

10.2.2.0/0.0.0.255 remote network

However, if all your spokes and hubs is compltely different subnets, then you must add lines in your ACL and network lists to include all this traffic.

Tags: Cisco Security

Similar Questions

  • all the research that lead to a result of site 'https' in "this connection is not approved.

    I was getting messages that update failed, I think that this has been caused by Lastpass update. I tried a refresh and my problem started. Tried to uninstall lastpass and FireFox then download Firefox (37.0.2), still have the problem. I can set Protopage as my home page, but all the bookmarks that lead to an https site get the untrusted connection. I tried several different search engines, same result. I'm running a 2011 mini mac environment. Please help I use FireFox for many years and many computers and I like it.

    Thank you!

    You can check who is the issuer of the certificates.

    You can retrieve the certificate and check details such as WHO issued the certificates and the expiration dates of certificates.

    • Click on the link at the bottom of the error page to expand this section: "I understand the risks".
    • Click on 'Add the Exception' and let Firefox to retrieve the certificate ('Get')
    • Click on the button "View" and inspect the certificate and the Coachman, who is the issuer.

    You can see more details like the intermediate certificates that are used in the Details tab.

    If this is not possible, then try this:

    Open the chrome URI by pasting or typing this URI in the address bar to open the window "Add the Security Exception" and to check the certificate:

    • chrome://pippki/content/exceptionDialog.XUL

    In the field location type and paste the URL of the Web site

    • retrieve the certificate via the button 'Get certificate '.
    • inspect the certificate via the "view..." button. »
  • I'm getting "connection timed out" when I try to connect to a specific Web site. I can connect to the site using Internet Explorer. Help?

    As suggested by Firefox, I've cleared my history and cache. Also, I downloaded and run one of the programs malicious applications recommended Firefox. I also deleted Firefox my firewall and then added it back as suggested by Firefox. I have no problem accessing the site using Internet Explorer.

    HTTPS Everywhere makes it easy for you to move site to a secure connection. It's something that you can yourself on the sites where you are displaying sensitive information, so it automates this for you, but I think that it is not essential.

    If you love the comfort, the extension has a function to create your own rules, as described on https://www.eff.org/https-everywhere/rulesets. It sounds a little complicated...

  • When I get e-mail with a site said to go to, when I click on the site it does not connect? Is there some kind of filter that prevents connection Web sites? Thanks, Jo

    When I receive an email with a Web site pointed out, even if I click on the site, I can not connect on the site.  Y at - it sort of a filter that prevents me to access the site and how can I fix this problem.  Thanks, Jo

    If you are using Outlook Express:

    Hyperlinks do not work in Outlook Express or in Word (revised 29-Apr-09)
    http://support.Microsoft.com/kb/823301

    Hyperlinks do not work in Outlook Express after you put upgraded to IE7 [or IE8] (revised 29-Apr-09)
    http://support.Microsoft.com/kb/929867

    If still no joy:

    With the permission of MVP Frank Saunders. [RIP]

    If nothing happens when you click on a link:
    Open Windows Explorer or on the control panel.
    Go to tools | Folder options | Types of files.
    Scroll to [NONE] URL: HyperText Transfer Protocol (NOT the shortcut URL: Internet) and select it.
    Click Edit or advanced, depending on your version of Windows.
    Choose 'open '.
    Click on change.

    "Application used to perform action" should read:

    "C:\PROGRAM may EXPLORER\iexplore.exe" - nohome (check the path to)
    Iexplore.exe to ensure that it is correct and use the double quotes).

    DDE should be checked and in the boxes below, you should have:

    #1:
    « %1 »,,-1,0,,,
    #2
    IExplore
    #3 (white)

    #4
    WWW_OpenURL

    Protocol URL: HyperText Transfer with Privacy should be the same.

    If the foregoing is correct, uncheck the box: use DDE.

  • When browsing from a page of the site appears "unable to connect" Although no connection problem

    When browsing from a page of the site appears "unable to connect".

    Hi Helen,

    Thanks for posting your query in Microsoft Community.

    Unfortunately, the question is not clear, please answer these questions so that we can understand the problem and help you better.

    1. which web browser you are using?

    2. what site you're talking about?

    3. this happens with all sites or with any specific Web site?

    4. What is the exact error message you are getting?

    5 have had any changes made to the computer before the show?

    If you are using Internet Explorer, follow the steps in the link.

    Can't access some Web sites in Internet Explorer

    http://support.Microsoft.com/kb/967897

    NOTE: Reset the Internet Explorer settings can reset security settings or privacy settings that you have added to the list of Trusted Sites. Reset the Internet Explorer settings can also reset parental control settings. We recommend that you note these sites before you use the reset Internet Explorer settings

    We would be more than happy to help you if the steps above did not solve the problem.

  • How to create a Web site that users can connect to?

    Hey guys

    How to create a Web site that users can connect to?

    How to create a site that users can connect to with steam, facebook, twitter, etc...

    See this discussion where a similar topic was discussed.

    Login using Muse and British Colombia page

    Thank you

    Preran

  • I have 2 accounts of adobe Setup and want to merge to 1. My Behance site is a different connection/e-mail than my creative cloud. So... When I'm connected to CC, I can't see my Behance site and updated. Can you please help?

    I have 2 accounts of adobe Setup and want to merge to 1. My Behance site is a different connection/e-mail than my creative cloud. So... When I'm connected to CC, I can't see my Behance site and updated. Can you please help?

    Please contact our support staff from the following link for assistance on this subject: https://helpx.adobe.com/contact.html

    (be sure to connect to adobe.com with your Adobe ID first)

  • New wifi router installed. Why do connect to sites but lose the connection as I browse even though Windows said excellent signal. To deactivate/activate

    New wifi router installed. Because then I can usually connect sites OK but when getting around a site or to another, I lose connection even though Windows said signal is excellent. Toggle heals the problem temporarily. Two tablets under the same roof using wifi even have no problem. There is no consistency in when the problem arises in any session. It happens in Firefox and Thunderbird. Close and restart the program does not help.

    I tried the reset and it was not good. Then I learned that my wife had a similar problem with his ipad I did what I should have done at the beginning, I restarted the router again. Hey presto, problem solved.

    Now, I'm off to eat some humble pie. Thank you, guigs2

  • History | Clearly all w / checked everything is disconnect me out of the sites that I am connected...

    I see reports of people who "do not keep history" who seem to have a similar result.

    I don't have this game, but manually erase all history (Yes, "Everything" (although "Forever" would be a better time-Word)) and Yes, all checkboxes checked... does NOTHING to clear log-ins. Many would be cleared with just Cache and Cookies are selected latest version / three days ago.

    This is a HUGE problem - I have not yet tried check that * nothing * is get authorized, but I will.

    Side note: I get some 'ghost' of the history menu on the left side, when he calls... I can see cutt off lines like:
    Copy, 0%, are dow (private window?), tory (history?) and ions (Options?) - the last three with partial visible icons.

    none of those are clickable...
    

    I guess you do not use a password manager, so the only way that you can load a new page as a logged-in user is if Firefox has sent one or more cookies that he was supposed to have cleared.

    If you rerun the experience, you can try:

    (1) load a relevant page on Yahoo, and then open the web console below (Ctrl + Shift + k). You can use this to check the next page, you load the tab to see what cookies Firefox is sending.

    (2) delete cookies using the ' clear history all ' you use, or just cookies, as you wish.

    (3) check if cookies from Yahoo survived by clicking on the padlock (or globe) icon in the address bar > more information > (Security tab) > button "show the Cookies".

    The list should be préfiltrée on the current site, and the list should be empty.

    Any aberration here?

    You can close this dialog box.

    (4) click a link in the Yahoo page to navigate (in the same tab) to another requiring page being connected.

    If Yahoo reacts as if you are always connected, click on the page request initial stated at the top of the list in the console web to display the request headers and cookies sent.

    Firefox has sent one of the cookies that should have been allowed?

  • Each site indicates that the connection is not approved

    Firefox has been very slow, so I did a restore. Now, all the sites that I try to go to-including the site in Mozilla support - says the connection is not approved. How can I fix this and again to solve the problem of slow browser?

    And now I get a message from script is not responding... that is IF I get on the site.

  • When I go on a site that requires a connection and automatically logged, I always get invited by the Office security software for master password. New w/Firefox 24.

    If I go to a Web site that requires a login and a password, and I have it configured to automatically sign in, I am automatically logged (he remembers username and password for this site), but the command prompt of the security apparatus of software for my master password appears. I can cancel the prompt and it goes, but it should not appear because I am already connected. This problem started to happen after I downloaded Firefox 24 yesterday.

    Start Firefox in Safe Mode to check if one of the extensions (Firefox/Firefox/tools > Modules > Extensions) or if hardware acceleration is the cause of the problem (switch to the DEFAULT theme: Firefox/Firefox/tools > Modules > appearance).

    • Do NOT click on the reset button on the startup window Mode without failure.

    Note that Firefox Sync also need to enter the master password.

  • A forum site does keep me connected

    This forum has a checkbox "automatically connect to each visit" who has worked on previous versions of FF, but will work on the most recent.

    I'm on a Mac.

    Websites to remember you and automatically log you on are stored in a cookie.

    • Create a cookie exception allow (Firefox > Preferences > privacy > Cookies: Exceptions) to keep such cookies, especially for sites Web secure and if the cookies expire when Firefox is closed.

    Make sure that you run not Firefox in private browsing mode.

    Private - browsing using Firefox without saving history all cookies are session cookies that expire if this session is over, so sites don't remember you.

    Do not use clear recent history to erase "Cookies" and "Site preferences".

    Compensation of the "Site Preferences" clears all exceptions for cookies, images, windows pop up, installation of software and passwords.

  • VPN from Site to Site RV325 to RV180 connection problems

    Hi all

    I am new to VPN and networking, please be patient with me.

    I recently bought a RV325 and a RV180 to create a site to site VPN Ipsec tunnel. I was not able to establish a connection between the two. I don't know that this is a setting that I have hurt or something on my part. I would be extremely grateful to anyone who can help me with this!

    I've attached screenshots of the two router... As I'm not sure what you guys would like to see.  If there is no specific details please ask and I'll give you.

    Thank you very much!

    Hello and thank you for the detailed information.

    I checked the configuration on both routers and found a few issues:

    First and the most important is the fact that on the two router WAN PII addresses use private IP by far. On the RV180W you 192.168.1.33 and you use on the 192.168.0.104 RV325.

    It's a big problem because it's showing that you're behind another router, which is the device that made the public IP address that you are trying to connect.

    To resolve this problem, you must call the ISP on both ends and ask them to change the modem in Bridge mode, that way the real public IP address will be assigned to the WAN 1 port on routers and you will be able to connect.

    The second problem I found is that, on the side of RV325, your LAN and WAN IP addresses are on the same subnet 192.168.0.x. Now, this problem will be solved once the modem is changed to the bridge, so nothing to change mode.

    Finally, I noticed that on the VPN configuration you use the 192.168.1.0 as the subnet for the RV180W, when, according to your screenshots, the actual LAN of the RV180W subnet is 192.168.2.1.

    One last thing is that I will recommend to disable the aggressive mode on each side of the VPN as opposed to have it turned on on both sides.

    I hope this helps!

  • VPN site-to-site with pppoe ADSL connection

    Dear

    I would like to know - is it possible to connect two 5505 ASA in VPN site-to-site with 1 site using the pppoe ADSL connection?

    A (static IP) site

    Site B (ADSL pppoe, DHCP)

    Site has < site="" to="" site="" vpn=""> > Site B

    Best regards

    Alan.

    Configuration of site B should be the same as all the other side than peers with static end.

    The different configuration would be on Site A as he will accept a VPN to a dynamic counterpart.

    Unfortunately, I have no configuration example to show you on ASDM.

  • Sites only show that connected primary vcenter.

    Hello. I'm under SRM with vCenter 5.1 5.1.1 update 1. Primary and secondary sites separated by a physical firewall. I followed the KB on ports:

    http://KB.VMware.com/selfservice/microsites/search.do?cmd=displayKC & externalId = 1009562

    I tested with telnet and I can connect successfully to SRM primary vCenter over 80 remote and vice versa remotely SRM to primary vCenter. Each vCenter can communicate successfully with their own local server of MRS. more 8095. In the primary vCenter, I am able to successfully establish the reciprocity, and after that I am prompted for the remote vCenter creds, I see both sites successfully connected.

    Now, when I jump on the remote vCenter (recovery site) I'm able to establish reciprocity between the two sites, but when the prompt to enter creds for the remote vCenter (main site), I get an error that comes up as "Impossible to connect to the remote server.

    Not sure where the problem lies. Any help most appreciated.

    Thank you

    Hi Stefan. Thanks for the reply. Only, I solved the problem. I asked our guys to firewall to create a rule to recovery side vCenter for the side protected vCenter via port 80/443. Yes, for vCenter vCenter. As soon as this rule, he creates my side recovery shows two connected sites. Now, the strange thing is that under knockout of SRM firewall rules, there is no vCenter vCenter rule to:

    http://KB.VMware.com/selfservice/microsites/search.do?cmd=displayKC&externalID=1009562

    The only reason for which I asked him to add this rule was because for some reason that was open from protected to recovery (port 80/443) vCenter vCenter and the side protected SRM plugin has been successfully showing as connected. Probably a good idea to include this item for later use.

    Thank you

Maybe you are looking for