Routing between sites that use the site to site VPN

I'm running 7.2 (1) two 515 who have a VPN site-to-site set up a bit as follows:

subnets of the main site - router main site - PIX1___Public IP's___PIX2 - remote site

The main site router: CAT6506 with engine SUP1A

Subnets listed in motor SUP:

SUB1 VLAN

IP address 180.x.1.x.255.254.0

VLAN SUB2

IP address 180.x.2.x.255.254.0

VLAN SUB3

IP address 180.x.3.x.255.254.0

VLAN SUB4

IP address 180.x.4.x.255.255.240

PIX1 is the subnet SUB4 (180.20.4.2)

Remote site subnet: 192.168.1.0/24

Route the engine by default Overtime toward another router that reached the internet via another public IP subnet.

Any host on SUB4 can reach any host on the remote site as long as the SUB4 host default gateway is the inside int PIX1 (180.20.4.2).

No matter what SUB4 host that uses the 180.20.4.1 address (router) default gateway cannot communicate with a remote host, but can communicate with any host from any subnet of the main site.

All remote hosts can communicate with any host on SUB4, regardless of the gateway of the SUB4 host address.

All remote hosts can communicate with the router on SUB4 main site, but can not reach one of the other interfaces subnet configured on the router.

I've added a static route on the SUP engine:

router IP 192.168.1.0 255.255.255.0 180.20.4.2

That did not help.

The uses of motor SUP EIGRP to learn other subnets main site reached through routers, so I added the remote subnet to that:

Router eigrp 10

redistribute static

network 180.20.0.0

network 192.168.1.0

No Auto-resume

No log-neighbor-changes to eigrp

No chance, no more.

I can't help thinking that I'm missing something very basic.

Any help is really appreciated

Hello

PLS, find the changes that must be made and checked.

PIX remotely:

1. you only need a default route and that you can route your subnets via inside as they are outside, so remove these statements

2.i see Access-group configured to be applied to the external interface for traffic coming from the outside, make sure that all required subnets are allowed.

3. in the access list for the corresponding traffic to cryptomap, I see that one included subnet, pls have all included traffic that must be encrypted (as sub1, sub2..)

Main PIX:

1. in the access list for the corresponding traffic to cryptomap, I see that one included subnet, pls have all included traffic that must be encrypted (as sub1, sub2..)

2. is there an 'access-group outside_access_in' access list present in the pix the corresponding traffic - check - the pls

3. by nat (inside) 0 access-list inside_nat0_outbound, include all your inside subnets that must have access to the remote subnet

L3 switch:

1.I see a default route pointing to your router 3640, so pls add a static route to your remote subnet pointing to Pix

IP route 192.168.1.0 255.255.255.0 x.x.22.2

2. pls check in your L3 switch, wheter the appropriate subnets sub1, sub2 are learned properly via the conifugred Eigrp VLAN respective

for example .sub2 and sub3 learning with leap following 8.2, sub 5 via 30.3

Pls try to understand the topology and make configuration changes and let us know the results

concerning

k VB

Tags: Cisco Security

Similar Questions

  • are there any current HP printers that use the HP 02 print cartridges? Old printer C6180 goes wrong.

    are there any current HP printers that use the HP 02 print cartridges? Old Photosmart C6180 printer goes wrong and have a lot of cartridges.

    The Site of HP Pageyield lists the following printers compatible with 02 cartridges:

    I do not believe there are all the models currently available that use cartridge 02.

    I heard that HP has (had?) a trade-in program for its intact packaging expired cartridges.  See this post for a suggestion.

  • Setting the properties of elements of façade in XControl to a VI that uses the XControl

    Hi all

    I'm new to XControls and I try to use them to make a generic digital indicator that fit into a matrix of waveforms of a similar measure and allow the user to display the first value of a waveform, it chooses by selecting the name of the desired channel in the waveform table. I have the XControl work, with a ring filled automatically with the NI_ChannelName of the input waveform array fields and the value of the ring being used to index the waveform table to select the appropriate data.

    What I want to do next is automatically set the value of control of ring in the XControl to the value that the user has selected the last time he ran the VI that uses the indicator. However, the properties of the control ring do not seem to be accessible from the VI that uses the XControl, and none of the XControl General properties seem to be accessible from the front VI in the XControl. The value of the ring is not part of the entrance of DataIn cable waveform table, so I don't have a good method to pass data to the control of the ring outside of what is in this table of waveform. I might add the value in the waveform table, if this helps, but indicators XControl do not transmit their return DataOut appellant VI to allow me to record the user selected value.

    Is there a good way to read and write the properties of façade elements in an XControl of VI that uses the XControl?

    I apologize for not posting my code; the computer with LabVIEW license is having network problems at the present time. I'll post the code when I can.

    Thank you!

    Erik

    In your State cluster typedef container, include a reference to a control of the ring.

    In your vi of façade, in the case of change of Direction, create a reference to your ring and connect to a plan by which he sends out the view state.  Also be sure to write true to the status changed in the result of the Action.

    In your xctl, select New-> property.  Name it after the property in the ring that you want to access.  Use the view clustered State (in your new property VI) to access the reference to the ring; son of a property node.  Change the control value in the appropriate type & connect to the property you want.

    Be sure to connect the path error through everything that might cause an error.

    When you drop an instance of the xctl and create a property from this node, your new property will be available.

  • My Webcam has problems detected by Skype and repeat myself there is another program that uses the webcam. Skype device code 43 usb video.

    My Webcam has problems detected by Skype and repeat myself there is another program that uses the webcam.

    Also got the guests when using Skype as a video device usb was not detected and that it is a code 43.

    Have tried several way sto resolve this problem. CyberLink YouCam HP's running came preloaded on the laptop. The webcam is running when this program is being used separately.

    Inappropriate Feedback Forum of Windows hardware and drivers Forum.

    My Webcam has problems detected by Skype and repeat myself there is another program that uses the webcam.

    Also got the guests when using Skype as a video device usb was not detected and that it is a code 43.

    Have tried several way sto resolve this problem. CyberLink YouCam HP's running came preloaded on the laptop. The webcam is running when this program is being used separately.

    Inappropriate Feedback Forum of Windows hardware and drivers Forum.

    Hello, Aadi467,

    A device driver has notified the operating system that the device failed.

    Run the diagnostic tool of hardware devices do not work or are not detected in Windows on the Microsoft Fix it Center.

    You can also uninstall the software from Cyberlink.  There is a found here download link to reinstall the software after restarting the computer.

    http://h30434.www3.HP.com/T5/notebook-operating-systems-and/lost-my-CyberLink-and-UCAM/TD-p/760367

  • Issue of multiple Disqualification tasks that use the same snapshot

    Details of the environment

    ======================

    Disqualification Version: 12.1.3.0.0


    A snapshot has been created in which the WHERE clause is outsourced and this snapshot table is used in a data quality process.

    Since there are different values passed to the WHERE clause, different jobs who have their own data quality process, but these process reads from the same snapshot table.

    Disqualification does not allow execution of different tasks that uses the same shot to run at the same time.

    Job1 is in operation, job2 throws an exception that the snapshot is locked.

    Any reason why Disqualification has this restriction? Processes are just doing a read on the snapshot table operation, so I was wondering why it was necessary to lock the object.

    We have more than 60 jobs that use the same snapshot and it would inhibit scalability if we are forced to run 60 jobs in sequence and not allow them to run in parallel.

    Can you advice how to fix this problem?

    The short answer is that each task must be executed with his own label of execution. Otherwise, each work is actually being run in the same context, and you will have problems of blocking.

    Please read on the labels of the execution and run profiles in the online help.

    Note that when running with a label of execution, complete results are not written; you need to decide exactly what to write work featuring the views of results you need. All data staged (including the snapshot itself) will be written with a label execution context and you can view the results in the Console of the server. Director will only show the results of the last run.

  • I've created a form that uses the value field text to fill the text of another field.  Does not take into account changes

    I've created a form that uses the value field text to fill the text of another field.  However, if I need to change the text, the second field does not update this change.  Instead of reset the form each time, is the Javascript code to update the fields if they have been modified?

    For example I Text1 and Text2.

    When I type in Hello in Text1 I see Hello in Text2.

    Later, if I decide to change to Goodbye Text1, Text2 remains Hello.

    The shape of the hoe can recognize this change?

    Thank you

    Edit: I think I have misunderstood the situation.

    If you want to both fields have the same value, just to give them the same name.

  • I'm trying to follow the video to "Change color" and I don't have a lot of options that uses the presenter.  I'm on a PC.  Can someone walk me by changing the color of an object step by step?

    I'm trying to follow the video to "Change color" and I don't have a lot of options that uses the presenter.  I'm on a PC.  Can someone walk me by changing the color of an object step by step?

    Sorry for the delay. Here is the video

  • Applications that use the non-public API will be rejected

    Hi guys

    Just read the iOS guidelines before getting too deep into the manufacturing of the native version of a web application.

    I was wondering what:

    Applications that use the non-public API will be rejected

    We hear when to submit an application in AIR - does that mean that you can not use your own custom classes?

    See you soon

    If you mean custom AS3 classes, Yes, you can use those. What you can't do, is create a DONKEY who calls in the frames of the iOS itself.

  • Calculation that uses the function Max Analytics

    Hello world

    Hope all is welll...
    I have 2 Calc:

    1) Calc_HippaToSortNumber who does:
    DECODE (hold desc, 'HIPAA', 999, NULL, 0, 500)

    2) Calc_MaxHoldDesc that uses the above calc in analytic function:
    Max (Calc_HippaToSortNumber) MORE (Student.Id PARTITION)

    I have a condition that uses the two Calc for:
    Select the line that corresponds to the max value of Calc by partition

    Calc_HippaToSortNumber = Calc_MaxHoldDesc

    I get the results I want, but I do not understand how works Discoverer:
    Calc 1 - should be the level of the detail line to assign a number based on a field to hold alpha Desc
    If keep Desc = Hippa, 999
    = Null, 0
    other values, 500

    Calc 2 - is an analytic function, so it happens after query calculates its results in detail

    BUT THE condition is testing the analytical function: this condition runs after the execution of the analytical function
    against all preliminary results?
    How does he know Scout to perform the function after execution of the analytical function
    instead of on the level of detail / row?

    The following test data:
    pls advise, tx, sandra

    ID take Fname Lname desc calc_HippatoSortNumber
    ==============================================================
    1 adams alice Certification BLS 500 max (500)
    2 Brown brett HIPAA 999 max (999)
    4 BLS Certification 500 Caroline Chin
    4 Caroline HIPAA 999 (999) max Chin

    I want to show only 3 lines using the analytical function max for the id field studying and comparing each
    the partition to the max value line and by selecting the line with the max value.
    1 adams alice BLS Certification 500
    2 Brown brett HIPAA 999
    4 Caroline HIPAA 999 Chin

    Hello

    How does he know Scout to perform the function after execution of the analytical function

    instead of on the level of detail / row?
    Discoverer always runs the latest analytical functions and therefore conditions by using analytical functions are also processed last. Discoverer for this by using a query online and therefore the structure of the SQLused

    Select Lname, Id, Calc_MaxHoldDesc, Calc_HippaToSortNumber)
    SELECT Id, Lname, DECODE (hold desc, 'HIPAA', 999, NULL, 0, 500)
    Calc_HippaToSortNumber, MAX (DECODE (hold desc, 'HIPAA', 999, NULL, 0, 500))
    ) Calc_MaxHoldDesc OVER (PARTITION BY Student.Id)
    Of...
    )
    WHERE Calc_HippaToSortNumber = Calc_MaxHoldDesc

    Rod West

  • How to use the library of Extension VPN

    Hello!

    I'll expand VPN enforcement using the library of Extension VPN. I already tried some time ago, but had no direct mechanism to develop and libvpn_ext library is not available on a simulator.

    I will use the library to open the VPN connection with a solution programmatically open source vpn, OpenVPN probably at the beginning.

    So question is, can I develop some app using this library for this application and then publish app on AppWorld?

    Thank you.

    I looked into the available VPN API, and they are not sufficient to set up your own VPN client.  So it is not possible to do what you describe.  I am not sure why we have listed what we do on our developer site.  They do not seem to offer enough to do something useful and probably just would induce in error the developers, as has happened here.  They may eventually be removed.  If I find more is coming I'll respond here, but it doesn't seem anything is imminent.

  • Is there a way to force Firefox 4 to offer to remember and to remember usernames and passwords for sites that use the AutoComplete mechanism to block these offers and memories?

    locked by a moderator, 07/02/2012 - has survived its usefulness

    In Firefox 3.6.16 (and probably other earlier versions) could force FF to offer to remember usernames and passwords for many sites by editing the file ...\Mozilla Firefox\components \nsLoginManager.js to ignore site - asked deactivate autocomplete (_isAutocompleteDisabled returns false).

    FireFox 4 does not use this file, or a similar one that I could find.

    The result (FF ignores site trying to disable AutoComplete) is possible in another way or by editing another file?

    This bookmarklet makes the browser ignore autocomplete = "off" temporarily, allows to save passwords even on sites that use autocomplete = "off".

    Don't forget to bookmark password:

    https://www.squarefree.com/bookmarklets/forms.html#remember_password

  • How to stop the connectivity between two computers that use the same IP address... ?

    Today, I managed to connect two computers with the same IP address. But now it is to be feared. for example, a person can access my computers using my IP and MAC address. So now, how can I stop the connectivity between these two computers. should what setting I use to stop.

    Tahnks.

    Hello

    1 have. what measures you taken to connect 2 computers with the same IP address?

    2. How are the 2 computers connected?

    3. how exactly you want to stop the connectivity between 2 computers?

    I want to tell you that 2 computers on the same network cannot have the same address. Each machine must have a unique address to identify it. A private network, as a home network connected to the internet, can be connected to a router to connect to the network, will have only 1 address, public IP address.

    In addition, if we know the IP address of a computer along the user ID and password, we can access the computer/shared files.

     
    If you are referring to the change of the IP address of the two computers, you can follow these steps and check.
     
    a. network connections open. Click the Start button, and then click Control Panel. In the search box, type 'adapter' and then, under center network and sharing, click view network connections.
    b. right click on the connection you want to change. Click on properties. If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.
    c. click on the network tab. Under this connection uses the following items, click Internet Protocol Version 4 (TCP/IPv4) or Internet Protocol Version 6 (TCP/IPv6), and then click the properties button. To specify your IP for IPv4, click on use the following IP address, and then, at the address IP, subnet mask, and gateway boxes by default, type IP address settings.
     
    A typical IPv4 address looks like 192.168.0.2; a typical subnet mask is 255.255.255.0. The default gateway is usually the address of your router.
    For example, IP address: 192.168.0.2 by 192.168.0.12 (for computers)
    Subnet mask: 255.255.255.0
    DNS: 192.168.0.1
     
    I hope this helps. If you have any other queries/issues related to Windows, write us and we will be happy to help you further.
  • Connectting to a modem that uses the Protocol PPPoA

    That's basically the problem.  There is no PPPoA options to select and I'm not sure what I should do!

    Thank you

    Mark

    OK, after losing an entire day on what I finallly got this job.  If you connect a Livebox to a router Linksys-WRVS4400N, using the Livebox as modem DSL (PPPoA) is what you need to do.

    1. find the version of the Linksys router.  Its on the router itself, mine was version 1.1

    2. update the firmware.  It's a pain to find.  The WRVS4400N is in the section of small business on the Cisco site.  You must then go to the model of router page and look very carefully through the links from the bottom.  I tried searching directly for it and seemed to have no chance.

    3. I think he should just keep resetting the router whenever you do something, but go to the Livebox configuration and change the settings of firewall to low.  The router will replace it.

    4. The Livebox is just a modem now so its probably to a value to disable the wireless network.  Then turn off the Livebox

    5. plug ethernet in the lan on the Livebox red and the other end into the Internet port on the WRVS4400N, switch on the Livebox

    6. plug WRVS4400 LAN 1 on PC.

    7. when it connected goto 192.168.1.1

    8 Hope you get login and see the installation/summary page.

    9. click on Setup - WAN and ensure that his auto in DHCP

    10. it's the bit you need to know.  Click on configuration - LAN tab and change the IP 192.168.2.1.  It's the missing piece!

    10.1 the setup page now is 192.168.2.1 to remember or you will fall with yourself!

    11 go back in the configuration - summary, then click on renew DHCP.  You should see the address IP WAN to change and the LAN IP 192.168.2.1 read.

    12 watch this world very satisfing appears on the logo of connections.

    I deserve a bloody Medal!

    Thanks to Linksys UK dept for your help and all the other bitty posts, I've read through to get this working.

    PS To change your pronto security settings and make sure your network attachments are behind the Linksys, not the Livebox!

    Mark Britton

    (Mod Note: deleted non-public information.) (Thank you.)

  • Discover which applications that uses the network

    Hello!

    I recently discovered that my computer sends tons of data thrown my internet connection every 20 minutes by analyzing the network graph in the Task Manager.

    Is there any application Windows witch allows me to find what applications uses the network. For example, the process and the use of the network?

    You can try this site:

    http://TechNet.Microsoft.com/en-us/Sysinternals/bb795532.aspx

    There are some tools that might help you.

  • BlackBerry 8310 Smartphone of Smartphones (BB has been DEAD for upgrading applications that use the Device Manager)

    Hello, recently I wanted to install an application but got an error message saying AJAX is not supported on your platform - after checking the forums on this site, I found that I need to upgrade to 4.5.X and for that I downloaded from this site the "8310M_PBr4.5.0_rel52_PL2.7.0.55_A4.5.0.37 [1].

    When I connect the device to the computer, I got the message from device manager asking if I want to upgrade applications to current version,

    I did it-but suddenly during the upgrade process, my blackberry is turned off and since impossible to turn it on again, it looks like my smart phone is completely dead! There's just a red light on the top flashing...

    That's all just amazing, because I have no idea why this happened because I used this official site and Device Manager was the one I downloaded from this site for 8310 Smartphone

    Can someone HELP me please?

    Thank you

    PAM

    Great!

    You please resolve this thread by using the options on the star of the kudo?

    Thank you very much!

Maybe you are looking for