The tunnel bridge LAN to LAN, is possible?

Hi all

We have this topology:

field of 192.168.1.0/24(Encryption)---[Dieudo]<====Ipsec tunnel="===">[VPNconcentrator]<==IPsec tunnel="==">[PeerB]---192.168.2.0/24 (field of encryption

The hub that we use is a 3000 series, I am eager to discover the will would be possible that 192.168.1.0/24 join 192.168.2.0/24 through the unique VPN hub. If the hub acts as a bridge between two tunnels.

If Yes, what is this called? and where you can find more information on this topology?

I think that this work would still need to test.

A counterpart assume encryption field 192.168.1.0/24 Source & Destination would be 192.168.2.0/24 using peer VPN Con.

Again on the field of encryption VPN would be same with remote peer even way around.

must be simlier to https://supportforums.cisco.com/docs/DOC-22428

Thank you

Ajay

Tags: Cisco Security

Similar Questions

  • PIX of Concentrator VPN tunnel, can I NAT traffic before the tunnel?

    I have a tunnel IPSEC of PIX-to-VPNConcentrator.

    I have a localhost on my PIX inside interface with the IP 192.168.5.5 but the site on the end of the tunnel VPNConcentrator wants to see the IP 192.168.77.9 (because they use the 192.168.5.x network to an end for another use)

    I know how things NAT from inside out, but I never have NAT - ed before traffic tunnel.

    Can I NAT a local inside IP address BEFORE traffic hits the tunnel?

    Yes, it is possible. Please see the below URL for the configuration details:

    http://www.Cisco.com/en/us/Tech/tk583/TK372/technologies_configuration_example09186a00800949f1.shtml

    Kind regards

    Arul

  • Dynamic L2L Tunnel - the Tunnel is up, will not pass the LAN traffic

    Hello everyone. I am repurposing an ASA for my business at a remote site and must use a dynamic Configuration of L2L with Split tunneling active. We used these in the past and they work a lot, and I've referenced Cisco official documentation for the implementation. Currently, I am having a problem where I am unable to pass traffic on the local remote network over the VPN tunnel (it does even not raise the tunnel of form). However, if I run the following command in the ASA remote:

    Ping inside the 192.168.9.1

    I receive the ICMP responses. In addition, this traffic causes the VPN Tunnel to be created as indicated by show ISA SA:

    1 peer IKE: xx.xx.xx.xx

    Type: L2L role: initiator

    Generate a new key: no State: MM_ACTIVE

    Here is the IP addressing scheme:

    Network remotely (with the ASA problem): 192.168.12.0/24

    Basic network (Hub): 192.168.9.0/24

    Other rays: 192.168.0.0/16

    Config:

    ASA Version 8.2 (1)
    !
    hostname xxxxxxxxx
    domain xxxxxxxxxxx.local
    activate the xxxxxxxx password
    passwd xxxxxxxxx
    names of
    !
    interface Vlan1
    nameif inside
    security-level 100
    192.168.12.1 IP address 255.255.255.0
    !
    interface Vlan2
    nameif outside
    security-level 0
    IP address dhcp setroute
    !
    interface Ethernet0/0
    switchport access vlan 2
    !
    interface Ethernet0/1
    !
    interface Ethernet0/2
    !
    interface Ethernet0/3
    !
    interface Ethernet0/4
    !
    interface Ethernet0/5
    !
    interface Ethernet0/6
    !
    interface Ethernet0/7
    !
    passive FTP mode
    clock timezone CST - 6
    clock to summer time recurring CDT
    DNS server-group DefaultDNS
    domain xxxxxxxx.local
    permit same-security-traffic intra-interface
    to_hq to access extended list ip 192.168.12.0 allow 255.255.255.0 192.168.0.0 255.255.0.0
    inside_nat0_outbound to access extended list ip 192.168.12.0 allow 255.255.255.0 192.168.0.0 255.255.0.0
    pager lines 24
    Within 1500 MTU
    Outside 1500 MTU
    ICMP unreachable rate-limit 1 burst-size 1
    don't allow no asdm history
    ARP timeout 14400
    Global 1 interface (outside)
    NAT (inside) 1 0.0.0.0 0.0.0.0
    Timeout xlate 03:00
    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    dynamic-access-policy-registration DfltAccessPolicy
    Enable http server
    http 192.168.0.0 255.255.0.0 inside
    No snmp server location
    No snmp Server contact
    Server enable SNMP traps snmp authentication linkup, linkdown cold start
    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac
    life crypto ipsec security association seconds 28800
    Crypto ipsec kilobytes of life - safety 4608000 association
    card crypto outside_map 10 correspondence address to_hq
    crypto outside_map 10 card game CORE peers. ASA. WAN. INTELLECTUAL PROPERTY
    outside_map crypto 10 card value transform-set ESP-3DES-SHA
    outside_map interface card crypto outside
    crypto ISAKMP allow outside
    crypto ISAKMP policy 10
    preshared authentication
    3des encryption
    sha hash
    Group 2
    life 86400
    crypto ISAKMP policy 65535
    preshared authentication
    3des encryption
    sha hash
    Group 2
    life 86400
    Telnet 192.168.0.0 255.255.0.0 inside
    Telnet timeout 5
    SSH timeout 5
    Console timeout 0
    management-access inside
    dhcpd 192.168.9.2 dns 208.67.222.222
    !
    dhcpd address 192.168.12.101 - 192.168.12.131 inside
    rental contract interface 86400 dhcpd inside
    dhcpd xxxxxxxxx.local area inside interface
    dhcpd ip interface 192.168.9.50 option 66 inside
    dhcpd allow inside
    !

    a basic threat threat detection
    Statistics-list of access threat detection
    no statistical threat detection tcp-interception
    WebVPN
    tunnel-group basis. ASA. WAN. Type of IP ipsec-l2l
    tunnel-group basis. ASA. WAN. IPSec-attributes of intellectual property
    pre-shared key xxxxxxxxxxxx
    !
    class-map inspection_default
    match default-inspection-traffic
    !
    !
    type of policy-card inspect dns preset_dns_map
    parameters
    message-length maximum 512
    Policy-map global_policy
    class inspection_default
    inspect the preset_dns_map dns
    inspect the ftp
    inspect h323 h225
    inspect the h323 ras
    inspect the netbios
    inspect the rsh
    inspect the rtsp
    inspect the skinny
    inspect esmtp
    inspect sqlnet
    inspect sunrpc
    inspect the tftp
    inspect the sip
    inspect xdmcp
    inspect the icmp
    !
    global service-policy global_policy
    context of prompt hostname

    Once the tunnel is in place, LAN to the Remote Site traffic won't pass through the VPN Tunnel any upward. On the side of ASA Core, I was able to Telnet in the ASA distance very well, but could not ping the Remote Access Point.

    Someone at - it a glimpse of my problem?

    Hello

    Add:

    NAT (inside) 0-list of access inside_nat0_outbound

  • Satellite R830-143, disconnect the other wireless LAN PC

    Just acquired a Satellite R830-143. Connects to my LAN fine wireless, BUT...

    I have three other computers connected to the local network both wireless, and as soon as I connect the Toshiba, the other three disconnects.
    If I turned off the Toshiba the other three reconnect back (although sometimes I have to reset the router).

    Have tried to move the Toshiba around the House, but the same result.
    Router is pretty old, but it works with other computers (an XP running, a Vista, a Windows7).

    Any ideas gratefully received. (This is my first Toshiba - I'm pretty impressed, but if I can't do network to my other PC it won't be a big purchase)

    Hello

    No other computers also disconnect if you connect the Toshiba Satellite LAN?
    AFAIK the R830 is equipped with card Atheros Wlan that supports standard network 802.11b/g/n.

    It may be possible that other laptops using the 802.11 standards of B and the Satellite R830 connects to the router using 802. 11 g.

    Please check the settings of your router and also check the R830 TCP/IP protocol.
    All laptops must use the same standard TCP/IP IPv4 or IPv6.

    Go to control panel-> network & sharing Center-> adapter change settings-> right click-> properties-wireless network card
    You will find the standard TCP/IP IPv4 and IPv6
    don't forget that IPv4 has been chosen!

  • my computer has two network icons, 1394 and con LAN. Either, especially the icon of LAN began to move to items being passed in the system tray when I start the computer.

    I have a new and strange behavior on my computer. Until recently, the two icons, 1394 connection and LAN icons always used to appear in the whole system tray after the computer has been started. Is no longer the case. Whenever I start the computer, I don't see the icon of LAN but discover that it attributed to items passed. Then I open the properties of the network connection, uncheck 'Show the icon in the system tray', click Apply + OK, then I open the properties, check the box again, click Apply + OK; only the LAN icon is displayed in the system tray. I'd appreciate any help with this problem. The situation is sometimes the reverse case, i.e., LAN icon appears in the system tray, but I find the icon to connect 1394 points ago. I put the properties in the Start Menu, the toolbar always showed.

    Hi ErhanKarabekir,

    1. Did you the latest changes on the computer?
    2. You have security software installed on the computer?

    Method 1

    Refer to the article below and try the steps mentioned, check if it helps.

    How to troubleshoot missing network connections icons in Windows Server 2003 and Windows XP

    http://support.Microsoft.com/kb/825826

    Method 2

    If the previous step fails to them it is possible that some third-party programs installed on the computer is causing the problem.

    I suggest that you put the computer in a clean boot state and check if it helps.

    To help resolve the error and other messages, you can start Windows XP by using a minimal set of drivers and startup programs. This type of boot is known as a "clean boot". A clean boot helps eliminate software conflicts.

    See the link below to learn more about how to clean boot.

    How to configure Windows XP to start in a "clean boot" State

    http://support.Microsoft.com/kb/310353

    Reset the computer to start as usual

    When you are finished troubleshooting, follow these steps to reset the computer to start as usual:

    (a) click Start, type msconfig in the search box and press ENTER.

    (b) If you are prompted for an administrator password or for confirmation, type your password or click on continue.

    (c) under the general tab, click the Normal startup option, and then click OK.

    (d) when you are prompted to restart the computer, click on restart.

  • Express Port Replicator II and Tecra A10 - 12Z - only the power and LAN

    Since my Toshiba T3600CT I received with docking station, I discovered that I have a docking station. In the meantime, I had a small Sony who had no docking station, for which I got one of the first USB docking station and since then I've seen always to get laptops with docking station.

    But this time something went really wrong, the Toshiba Express Port Replicator II PA3680E-2PRP provides only power and LAN. There is no power in the USB ports, so no serial port or the sound, and DVI and VGA are also disabled.

    All these ports work fine on the Tecra A10, but not on the docking station.

    Of course, it is nice to have the power and LAN, but not when I expected too much of everything.
    So I was wondering if anyone has had a similar problem, it is like upgrading the BIOS for me who have not installed all the necessary software, or is it a fuse or something I could fix myself or is it a faulty docking that shouldn't have left the factory?

    Hello

    What's your Tecra pre-installed with original recovery image?

    When the laptop is preinstalled with recovery image simply connect compatible laptop Toshiba docking station and all the devices connected to the docking station will be recognized correctly and all available ports should work fine.
    Is that a Port Replicator basically "replica" ports on the laptop.

    On this virtual path, we cannot say that this port is 100% OK. What can you say about it? you bought is used a?

  • Slow internet speed because of the Marvell Yukon LAN driver

    Hi all!

    I'm a newbie here so don't know if I'm supposed to ask this question here but anyway, hope, my problem is solved somehow.

    I'm on a Toshiba Satellite A200 laptop computer, I received last week and everything works well except my internet speed, its too slow. I'm on a 10 Mbps plan but my speed is no where near that. I get speeds close to 200 kb/s at 300 KB/s max. After some googleing I got to know that the Marvell Yukon LAN driver is the problem here.

    According to some Internet sites, we are supposed to roll back the driver to a previous version, I did it, but speed still does not pass. I have tried almost all the things I can do, but nowhere so far. I called my ISP, they say that everything is rosy on the other hand, ran the scan of Norton Antivruis on this computer, the firewall disabled, and the list is long but nothing.

    It would be great if someone could help me out here.

    Thanks in advance...

    Hello

    checked your connection with another computer, if the problem persists try with another machine?

    Would be really interesting... If not I suggest you to reclaim your machine to 'default '. Maybe it's solved something.
    Another idea would be to remove the service from the "Qos" (quality of service) of your network connection, which hardly slows down the connection for software reasons.

    Please give some feedback and please tell me what system you´re using (Vista, XP)

    THX

    Good bye

  • EliteBook 8460p: at the same time LAN &amp; WLAN using problem

    Hello

    I can't use my elitebook 8460p network (LAN), Wireless Network (WLAN) and local at the same time. Both are well configured. The sequence is that when I connect the official LAN in the laptop cable, existing wireless network automatically becomes invalid. If I unplug the LAN, WIFI will automatically connect to the network. Why this is happening, I don't know. Please, help me.

    Info:

    * windows 7 Professional 64-bit.

    * If I press the key again wlan connection both LAN and WLAN, it does not work and will automatically reconnect if the network cable is unplugged.

    I know this isn't OS related issue. I know well on the network configuration. It is the first case and applies only to this model (here 8460p). If there is any related issue of BIOS, please help me. I developed, but not found.

    Help me, please.

    Hello:

    There is a setting in the BIOS called LAN/WLAN switching.

    The setting is enabled by default.

    If you want to have the wireless and ethernet, working at the same time, go into BIOS, find and disable the LAN/WLAN, commissioning, save the changes and exit the BIOS.

  • When I connect the USB and LAN cable does not my trackpad

    Hey guys how are you.

    When I connect the USB and LAN cable does not my trackpad

    How can I fix this error. Please teach me.

    Which macbook model do you have?

    a USB mouse still works?

    your keyboard still works?

    No matter which USB port you use?

    No matter what USB device allows you to create this error?

  • What happens if I uncheck all the properties of LAN (Local Area Network)?

    What happens if I uncheck all the properties of LAN (Local Area Network)? My machine OS is Windows XP Home Edition / 2002 Version / SP3 and I have a wireless connection. My connection to the LAN is disabled, currently, I don't have the desire to create a network, and I will in the future.

    Hi Bobby Collas,.

    There is no problem, when you turn off all the options in the properties of the local area network (LAN).

    You will not be able to connect to the Internet or use the connection to the Local network.

  • Support for the 'grouping' Dual LAN

    I bought a router of WRT600N, which was far & away the router wireless dual band to use more expensive (& only) available at the time + 2 compatible Ultra Range Plus USB receivers.  Apparently Linsys/Cisco decided to abandon this model & more support - still firmware version 1.0 (from 2008).  OK, then repeat ceMarketing not high on their priorities.

    I recently upgraded my hardware in a platform Intel 1156 running Win 7 Ultimate 64-bit completely.  The new motherboard, a Gigabyte GA-P55-UD5, has a 'dual LAN' support that allows "bundling" - potentially 2 GB support & self-switching if a port is not functional.  Apparently, it requires a router that has 'IEEE 802.3ad' capabilities.  As far as I can tell, this potentially interesting feature only is not supported, & the firmware upgrade failure suggests it will be never. - bought their "Network Magic" software Pro to add another $50.

    So the question is this: I believe - no double support LAN is built in & never will be--or is there a way to use this feature?  Suffice to say, if I paid about $420 for the router & USB receivers where if other router support him on the level of consumption, I will never consider a Linksys/Cisco product in this life.

    Thanks for some clarity - that someone has to offer.

    I would say the associations are no consumer router function. If you really need a connection of 2 Gbps to a single device to your network, I wonder what other device to communicate with this speed. It is not only another device because it would have only 1 GB/s unless you team two remaining ports as well. (Do not forget that desktop computers more level of consumption are not yet fast enough to offer or receive data at a rate even if they have a Gigabit ethernet port).

    If you have a set of other features which, in combination, require 2 Gb/s access server, then you will have again the same problem: it must connect somewhere which means you need a switch that must be connected to the two remaining LAN ports. But then, you might as well get a switch that supports reunification and enough ports and connect everything what he. Of course, an ethernet switch that supports the grouping is usually some 'smart' managed switch that cost easily more then your WRT600N.

    So I think that grouping will be never supported on any Linksys consumer device. If you then you must watch the Cisco Small Business series or better. They have some devices supporting 802. 1 q VLAN and therefore potentially also 802.3ad. Although even in this case I doubt because given the number of ports available on these devices is not really a lot of sense to support at least on a router 4 ports. Devices consumer and SOHO are not for internet connections of 1 Gbit/s or more. So you can only use the speed inside the LAN, but with 4 ports that would be difficult... So I would say that by their design these routers don't support grouping. If you need grouping within your LAN, get a managed switch...

  • Vista PC is offline, unable to connect to the Internet by LAN or wireless.

    Original title: Vista (Japanese OS)

    My Vista pc is offline (unable to connect to the internet), how install and run the Fixit tool?

    I have read that the English, however, my pc is in Japanese. I can't connect to the Internet by LAN or wireless.
    How can I get the Fixit tool to work on the said pc?
    Help, please!

    Hello

    1. what Fixit tool you try to run?

    2. what exactly happens when you try to connect to the Internet? You receive messages or error codes?

    You can read the following article and check if it helps:

    Windows wireless and wired network connection problems

    You can also read the following article to change the display language:

    Change the display language

    You can use another computer to download the Fix from Microsoft, then use portable storage such as a USB drive, CD, DVD, etc., to carry the Microsoft fix it on your computer.

  • Internet does not work on Windows 7, no drivers for the Wifi and LAN

    Original title: Windows 7

    I used to have Windows 8 on my laptop. Well, so I've updated for Windows 10. Config my laptop wasn't as good, so it's slow. Recently, I installed Windows 7 (as it is known for the performance) somehow, the internet does not work. Missing the drivers for the wifi and lan. What should I do?

    Well, as my readers usb and touch screen no longer work.

    You have installed Windows 7 on a machine that is preinstalled with Windows 8, without checking first if the computer manufacturer supported and provided Windows 7 drivers for it.

    If does not support or provide Windows 7 drivers for this, you should never have installed Windows 7 on this computer Windows 8 and we cannot help you.

    Reinstall Windows 8.

  • How can I choose the local computer lan ip in forms6i?

    How can I choose the local computer lan ip in forms6i?

    This:
    Re: identifier must be declared.

    is a complete solution. It only will be not all then more detailed which. Surely you know how to create a stored procedure not you? Connect to SQL * more to your database and paste the displayed code from Paul. Then call this procedure of forms.

    see you soon

  • Cannot ping vpn client of 1721 cli on the tunnel endpoint

    I have a 1721 fortunately supporting ipsec vpn client connections. With one small exception, everything works perfectly fine.

    The VPN pool is 10.10.10.1 - 10.10.10.254

    The interface internal f0 is attributed to 192.168.1.254/24.

    In my example:

    Ip address of the VPN client is 10.10.10.5

    The host address of an arbitrary machine on the internal lan is 192.168.1.151

    I am able to ping 192.168.1.151 10.10.10.5

    I'm * not * able to ping 10.10.10.5 192.168.1.254 using the cli on the 1721.

    There is a very good reason to want to solve this problem. I would like to be able to access a tftp server on the client vpn directly from the router in order to download the new startup-config files. Is it possible to get the traffic of vpn-/ tunnel-point endpoint client tftp to travel through the tunnel?

    When you ping from the CLI on the router, the packet will be from the external interface, not the IP address fa0 interface. The VPN client and the router only built a tunnel from the 10.10.10.5 address the 192.168.1.0 network, then the router not cryptera a package that her origin is outside the IP address.

    Try to ping extended to 10.10.10.5 and source of 192.168.1.254 package and see if it works. If it does, you will have also to the source of your TFTP packets from inside interface, you can do with:

    IP tftp source interface fa0

Maybe you are looking for

  • Satellite Pro L20 - slow DVD burning speed

    Hi all I have a very annoying problem with my optical drive - he writes only CD at 6-8 x and DVD x 2! Nothing more! I have read several forums and it seems I'm not the only one with this problem. Only, it seems that there is no solution for this prob

  • Tecra A2 - need XP drivers for LAN and WLan card

    Hey,. I have a little old... computer laptop Toshiba Tecra A2 of second hand and apparently his need for an ethernet controller and network controller player.I used the website of toshiba to download many drivers for this laptop model successfully. I

  • Yoga 2 Pro - cursor flashes when moving on some programs

    I have a Yoga 2 Pro with Windows 10. Some programs (for example Thunderbird, LibreOffice), the cursor flashes when moving on the program window. I made sure my screen and touchpad drivers are up to date as well as the BIOS of my laptop. What else cou

  • Find the replacement battery - "low battery alarm.

    I'll have to re - use a PC that has a 'bad' C-drive for now was "butterfly of the night-balled" years, but at least it market, becuse of the XP Virus on my machine good 2012.  Man, is that what noise disc c, etc. etc. Anyway, I was wondering, since I

  • Stop abnormal error Windows XP

    Original title: help stop Even after that all programs closed and stop I still have the wrong stop message how to clean it