Use the client VPN tunnel to cross the LAN-to-LAN tunnel

I have been troubleshooting an issue and cannot cross an obstacle. The ASA is running ASA running 1,0000 code 24. I am using a client VPN tunnel to connect to the ASA. The ASA has already a LAN-to-LAN tunnel, set up and operating and I need the VPN client to access the remote site over the LAN-to-LAN tunnel.

The internal IP address of the local part is 192.168.0.0/24 and the IP address of the Remote LAN-to-LAN tunnel is 172.20.1.0/24. The clients are distributed 192.168.200.0/24 IPs. I have attached the relevant configuration for the SAA.

When the VPN client on the network, I can access resources on the ASA network internal. On the internal network of the SAA, users can access resources through the LAN-to-LAN tunnel. Client VPN cannot access resources on the LAN-to-LAN tunnel. For the latter, there are no hits on the C-TEST access list.

Thank you for your help.

try adding...

permit same-security-traffic intra-interface

http://www.Cisco.com/en/us/products/ps6120/products_configuration_guide_chapter09186a00806370f2.html#wp1042114

Tags: Cisco Security

Similar Questions

  • Can I use the lan Ethernet port on the airport express to the release of music?

    Can I use the Ethernet connections on airport express at the exit of music over wifi to a set of speakers? I would use an Ethernet connector at one end a DIN 5 pin to a pair of speakers beolab 2500/2300. I don't want to use the PIN audio output on the Airport express, as it is analog. Possible music out through one of the Ethernet connections at the back of the Airport express? Thank you

    Can I use the Ethernet connections on airport express at the exit of music over wifi to a set of speakers?

    Sorry, but no.

    I don't want to use the PIN audio output on the Airport express, as it is analog

    Perhaps you weren't aware that audio port on the AirPort Express audio book Terminal analog or digital, according to the type of connector used. See this link on the AirPort Express specifications to confirm... http://www.Apple.com/Airport-Express/specs/

    In other words, for the Express deliver audio analog, connect a standard stereo mini plug with connectors appropriate to the other end.  To ensure that the Express deliver audio digital, plug a mini Toslink cable to the audio port on Terminal AirPort Express.  An example is in this link... Airport Express Toslink - Amazon.com

  • Satellite L850 - unidentified network, try to use the LAN card

    I have the Satellite L850 and were using the wireless without any problem.

    Now I find that I can't get the network to work just by using my Ethernet cable.
    I tried to turn off the wifi and allowing the PCIe realtech family responsible of the treatment, which is the connection to the local network, but I get unidentified network.

    Y at - it a sort of conflict between wifi even if it is disabled and the connection to the local network.
    I'm pulling out my hair. The LAN worked very well until I decided to try the WIFI.

    Hello

    The unidentified network problem may be related to different causes, and therefore different workaround solutions may be possible.
    First of all I recommend you to uninstall the network adapter driver.
    This can be done in the Device Manager. After the driver has been removed, restart the laptop and install the network driver that you can download on the page of the Toshiba driver.

    2nd solution: reset the reset TCP/IP protocol
    To do this, see the article Microsoft Knowledge base:
    http://support.Microsoft.com/kb/299357

    Check also if you tools of security (firewall, antivirus software, Mcafee) n does affect network connectivity.

  • Dell Latitude 10 + 8.1 Windows Pro + Docking Station = not in position to use the LAN connection?

    I have a dell Latitude 10 that I had just upgraded to Windows Pro 8.1, everything seems to work fine except for the LAN on the docking port, I tried all the old and latest versions of the drivers 7500LANUSB out there with no success to get it to work properly.  All the other ports in the station properly.  I also tried with another Dell Latitude 10 w\ Windows 8 and works very well.  Also with another Tablet that has Windows 8.1 with the same result as the first with not able to use the connection to the LAN on the dock.   PLEASE HELP ME!  I have 93 of these devices that we will upgrade to Win 8.1 via WDS, but it can't happen until this is resolved.

    I confirmed that a tablet of 10 Latitude running Windows 8.1 is able to connect to a wired LAN docked. I was able to get a valid IP address with the unit that I was testing.

    Have a look in Device Manager and make sure that your driver LAN7500 looks like this:

    You may completely uninstall and then reinstall the driver of LAN7500 of time management devices and programs and features.

    You can download the current version of the LAN7500 here:
    http://www.Dell.com/support/drivers/us/en/04/product/Latitude-10-Tablet

    the name of the file is LAN7500_Win8_A04_Setup - R84GF_ZPE.exe and it will run on Windows 8 and Windows 8.1

    Please let us know if the problem persists.

  • Satellite P100-188 - cannot use the LAN driver listed on the download page

    Hello

    I've recently changed this laptop Windows XP MCE. I got all the drivers out of the Toshiba download except the network card page. Both versions, it lists only containing an 'uninstaller '.

    Does anyone have any ideas where I can get a driver to make this work?

    Kind regards

    Matt

    Download the driver and extract the contents into a new folder created. Please enter the LAN card properties in Device Manager and choose the option to install the driver. Asked about the driver choose navigate to this new created folder and see what happens.

  • How to connect Network Analyzer Agilent 5062 A with LabVIEW 7.1 using the LAN interface?

    Hello

    I have change a program to remote control Agilent 5062 A by NOR-GPIB.

    I would change the LAN interface. but I don't know how to change the name of resource VISA.

    another, I would like to put this S/W in HD 5062 A also the LAN issue must be resolved.

    Who has edit reonmote experience-5062A controlled interface LAN LabVIEW (7.1), share me, thank you.

    Thank you.

  • HP Officejet Pro X576dw: Wireless Direct Printing using the Lan cable

    Hello

    I buy HP Officejet Pro X576dw multifunctional on tomorrow. I understand that this printer has a direct wireless printing features that I can print from my tablet or IPad.

    But I doubt if this wireless direct printing can be done while the printer is connected to the network via Lan cable permanately IPV4.  This means I can print from my mobile phone at anytime via Wireless Direct without the Lan cable.  Kindly advice. Thanks in advance.

    David

    Oh, which means that you simply unplug the Direct SSID wireless and you should be able to print via your router LAN cable now.

  • How to use the LAN wireless on a Satellite L100-197

    Have this L100-197, has a card wireless in there, but the wireless button is blocked with a sticker. Installed the card very well, but obviously I have no wireless switch, so it can't seem to find available networks.

    What do I do/buy/install?

    [Edited by: admin on June 30, 2007 08:04]

    Hello

    Do you really mean the Satellite L100-197? !!! This laptop is not known to me!
    It seems that the number of 197 extension does not exist but only the 179!

    Satellite L100-179 does not support WLANs and was delivered without any WLan minPCI cards!

    Bad news, you can also not improve with a minPCI wireless network card. If you want to connect the laptop to the WLan, you need to use an external solution such as a WLan USB key for example!

    concerning

  • Using the LAN Voice feature

    I'm spending some old HP/3Com switches for some new Dell PowerConnect 62xx and 55xx switches v1910.  The EPS and the 55xx all have a function of 'YES' where I can specify that the first six characters of my IP phone manufacturer mac address so that the phone can automatically be assigned to the VLAN correct.  62xx switches have not however of this feature.  How do I know the 62xx switches should assign a phone to VLAN 2 when the phone starts?  Our PC is plugged into the PC ports on the phones themselves and they must be on the VLAN 1 is not possible to attribute specific to ports VLAN individual.  I'm sure I'm missing something somewhere but I don't know what.

    Any ideas would be much appreciated.

    Thank you.

    -Chris

    Hi Chris,

    Here is the guide for the characteristic voice VLAN http://www.dell.com/downloads/global/products/pwcnt/en/pwcnt_voice_VLAN_support.pdf

    How it works, is that phones are tagged with the VLAN that you assign and the PC traffic is sent without a label.

  • Client VPN connects but not internal LAN access or Ping

    Hi all.

    I'm new on this forum and kindly asking for your help because I'm stuck.

    I have an ADSL router cisco 877 which I configured easy VPN server.
    Now the Cisco VPN client ver 5.0 to connect successfully to the VPN server, but when you try to access/ping computers on the internal network, there is no response.

    The configuration is below. Please let know us where I was going or what I missed.
    [code]

    Building configuration...

    Current configuration: 4574 bytes
    !
    version 12.4
    no service button
    horodateurs service debug datetime msec
    Log service timestamps datetime msec
    encryption password service
    !
    boot-start-marker
    boot-end-marker
    !
    enable secret 5 $1$ $86dn J8HrK9kCQ8G9aPAm6xe4o1
    enable password 7 13151601181B54382F
    !
    AAA new-model
    !
    !
    AAA authentication login default local
    AAA authentication login internal_affairs_vpn_1 local
    AAA authorization exec default local
    AAA authorization internal_affairs_vpn_group_1 LAN
    !
    !
    AAA - the id of the joint session
    !
    Crypto pki trustpoint TP-self-signed-2122144568
    enrollment selfsigned
    name of the object cn = IOS - Self - signed - certificate - 2122144568
    revocation checking no
    rsakeypair TP-self-signed-2122144568
    !
    !
    TP-self-signed-2122144568 crypto pki certificate chain
    self-signed certificate 03
    30820248 308201B 1 A0030201 02020103 300 D 0609 2A 864886 F70D0101 04050030
    2 060355 04031326 494F532D 53656 C 66 2 AND 536967 6E65642D 43657274 31312F30
    69666963 32313232 31343435 6174652D 3638301E 170 3032 30333032 32303537
    31375A 17 0D 323030 31303130 30303030 305A 3031 06035504 03132649 312F302D
    4F532D53 5369676E 656C662D 43 65727469 66696361 74652 32 31323231 65642D
    34343536 3830819F 300 D 0609 2A 864886 01050003, 818, 0030, 81890281 F70D0101
    8100D3EA 07EC5D66 F4DD8ACC 5540BDBE 009B3C26 598EC99C D99D935A 51292F96
    F495E5A9 8D012B0E 73EA7639 3B 586799 187993F5 ED9CA31C 788756DD 6BDB1B2B
    4D7AA7F0 B07CF82F F2A29E86 E18B442C 550E22D2 E92D9914 105B7D59 253BBEA1
    D84636B4 A4B4B300 7946CE84 E9A63D2E 7789B03A 6ADDB04E B21EC207 CCFEAE0B
    30 HAS A 50203 010001, 3 1 130101 301B 0603 030101FF FF040530 0F060355 70306E30
    551 1104 14301282 10494E54 45524E41 4C5F4146 46414952 53301F06 03551D 23
    04183016 8014FA0F B3C9C651 7FD91EFA 3F63EAE8 6C83C80D 8AE2301D 0603551D
    0E041604 14FA0FB3 C9C6517F D91EFA3F 63EAE86C 83C80D8A E2300D06 092A 8648
    86F70D01 01040500 03818100 A1026DDC C91CAEB2 3C62AF92 D6B25EB2 CA 950, 920
    313BCF26 4A35B039 A4F806A0 8CB54D11 6AF1ABAA A770604B 4403F345 0351361B
    E2CF2950 26974F4A 95951862 401A4F76 C816590C 2FFCB115 9A8B3E96 4373FFE1
    33D744F7 E0FDDE61 B5B48497 9516C3C6 A3157957 C621668E A83B5E33 2420F962
    9142DD9E B6E9D74A 899A 9653
    quit smoking
    dot11 syslog
    IP cef
    No dhcp use connected vrf ip
    DHCP excluded-address IP 10.10.10.1
    !
    IP dhcp pool dhcplan
    Network 10.0.0.0 255.0.0.0
    DNS-server 196.0.50.50 81.199.21.94
    default router 10.10.10.1
    Rental 7
    !
    !
    property intellectual auth-proxy max-nodata-& 3
    property intellectual admission max-nodata-& 3
    name of the IP-server 81.199.21.94
    !
    !
    !
    VPN username password 7 095A5E07
    username fred privilege 15 password 7 1411000E08
    username ciscovpn password 7 01100F175804101F2F
    !
    !
    crypto ISAKMP policy 1
    BA 3des
    preshared authentication
    Group 2
    !
    ISAKMP crypto client configuration group internal_affairs_vpn
    key *.
    DNS 196.0.50.50 81.199.21.94
    pool ippool
    ACL 108
    !
    !
    Crypto ipsec transform-set esp-3des esp-sha-hmac RIGHT
    !
    Crypto-map dynamic internal_affairs_DYNMAP_1 10
    Set transform-set RIGHT
    market arriere-route
    !
    !
    card crypto client internal_affairs_CMAP_1 of authentication list internal_affairs_vpn
    card crypto isakmp authorization list internal_affairs_vpn_group_1 internal_affairs_CMAP_1
    client configuration address card crypto internal_affairs_CMAP_1 answer
    ipsec 10-isakmp crypto map internal_affairs_CMAP_1 Dynamics internal_affairs_DYNMAP_1
    !
    Archives
    The config log
    hidekeys
    !
    !
    !
    Bridge IRB
    !
    !
    interface Loopback0
    2.2.2.2 the IP 255.255.255.255
    !
    ATM0 interface
    no ip address
    ATM vc-per-vp 512
    No atm ilmi-keepalive
    PVC 0/32
    aal5snap encapsulation
    Protocol ip inarp
    !
    DSL-automatic operation mode
    Bridge-Group 1
    !
    interface FastEthernet0
    !
    interface FastEthernet1
    !
    interface FastEthernet2
    !
    interface FastEthernet3
    !
    interface Vlan1
    description of the local lan interface
    IP 10.10.10.1 255.0.0.0
    IP nat inside
    IP virtual-reassembly
    !
    interface BVI1
    internet interface Description
    IP 197.0.4.174 255.255.255.252
    NAT outside IP
    IP virtual-reassembly
    internal_affairs_CMAP_1 card crypto
    !
    IP local pool ippool 192.168.192.1 192.168.192.200
    IP forward-Protocol ND
    IP route 0.0.0.0 0.0.0.0 196.0.4.173
    !
    IP http server
    local IP http authentication
    IP http secure server
    IP nat inside source list interface BVI1 NAT overload
    IP nat inside source static tcp 2.2.2.2 23 23 BVI1 interface
    !
    NAT extended IP access list
    allow an ip
    !
    access-list 108 allow ip 10.0.0.0 0.255.255.255 192.168.192.0 0.0.0.255
    !
    !
    !
    control plan
    !
    Bridge Protocol ieee 1
    1 channel ip bridge
    !
    Line con 0
    password 7 0216054818115F3348
    no activation of the modem
    line to 0
    line vty 0 4
    password 7 06160E325F59590B01
    !
    max-task-time 5000 Planner
    end

    Since this is a named ACL, you need to change ACL configuration mode:

    NAT extended IP access list

    Then, make the changes.

    Federico.

  • Authentication PEAP wireless across the VPN tunnel

    We use routers for Cisco 871 VPN connectivity series. I'm testing the 871W for VPN and wireless connectivity. I am able to get the VPN but have problems with authentication using PEAP and authentication through active directory wireless. The problem is that my router is unable, because of the VPN connection, "talk" directly to my authentication server using the LAN ip address. I can get the authentication works if I pass the traffic through the internet, drill a hole in my firewall to complete the authentication process. This isn't my preferred method. What can I do to work around may lists VPN access that prevent my direct connectivity to my server?

    Are you able to ping to the ip address of the radius through the tunnel server?

    Try adding this:

    radius of the IP source-interface BVI1

    * Please rate if helped.

    -Kanishka

  • Using Cisco VPN Client VPN

    Is it possible to use a private network virtual created with the WRVS4400N router with VPN Client from Cisco Systems (ver 5) software? (Although QuickVPN works very well.)

    Is it possible to use with Account customer VPN mode? Or is it possible to use with IPSec VPN (Tunnel) mode? If so, please provide together how to client-side and the router. Thank you!

    Unfortunately Small Business routers are not compatible with the Cisco VPN Clients. The Cisco VPN Clients have more parameters that are not available in the materials of the series of small businesses, so all we can use is the application of QVPN.

  • Using the Ethernet Port on a remote Express

    I have just moved into a new House and has Verizon FiOS installed.  Verizon provided a router modem combination like my main wireless service.

    I have an IP phone that I need to use in my office located in another room and the Verizon tech said that it would be very expensive to run a separate line in this room.

    I have a generation current Airport Express.  I would like to use the Express to join/expand the wireless network in the office, but my question is, the LAN on the Express port will be active so that I can connect the IP phone to the LAN port and use the phone via wireless Express?

    If possible, can you give us some guidance on how to configure the Express?

    Thank you

    David

    I would use the Express to join the network wireless Office

    The AirPort Express, expected to be able to 'join' the wireless network that is provided by the modem/FIOS router, assuming that the device uses wireless standard... parameters and... He Express is located where it can receive a strong signal of the FIOS router/modem wireless.

    But, the Express can not "extend" or "repetition" of the FIOS wireless network, given that "expand" function requires the Express receive a wireless signal from another Apple wireless router.

    .. .my question is, the LAN on the Express port will be active so that I can connect the IP phone to the LAN port and use the phone via wireless Express?

    Yes.  In fact, you can use the LAN or WAN port, or both at the same time... because both ports behave as LAN ports when the AirPort Express "joins" a wireless network.

    can you give us some guidance on how to configure the Express?

    What camera... Mac, PC, iPhone / iPad... will you use for this?  What operating system is that it uses?

  • Satellite 1800-100: a kind of metal in the LAN port

    I have an old S1800-100 (about 4-5 years), there is a kind of metal in the front where I (would) attach my ethernet cable. It is a problem since I finally had time to DSL. I'm sure this is a silly question, but it does not mean that I do not have a card? What should I do? Buy a card and install or buy a new computer?

    / Catharina

    Hello

    Network port on this unit is not available. You can use the LAN PCMCIA card. I'm sure that this card is not expensive. Check it out at your local retailer.

    Good bye

  • Satellite Pro U300 - how to go if connected to the LAN WiFi

    How can I change my laptop to the wireless router, when you connect to the internet LAN?
    My laptop is Toshiba Satellite U300 pro

    Post edited by: marto_noa

    Unplug the cable LAN and switch ON the WLan.
    Usually the laptop would use the LAN connection if LAN cable is connected and LAN is active.

Maybe you are looking for