VPN connects, cannot get to anything on the LAN

OK, what don't get me?  My VPN connects OK with the Version of the Client 5.0.07.0290 VPN but I can't access anything on the 10.0.0.0/24 network.

Any thoughts?  I should be able to ping the server 10.0.0.90 if it worked properly in my laptop while I'm on the VPN.  Following configuration:

ASA Version 7.2 (4)

!

hostname XXXX

domain energy.com

activate jp28ZvYIS1PQVK6M encrypted password

UmzM9i7pSqpXEdTR encrypted passwd

names of

!

interface Vlan1

nameif inside

security-level 100

IP 10.0.0.9 255.255.255.0

!

interface Vlan2

nameif outside

security-level 0

IP address 74.x.x.150 255.255.255.248

!

interface Ethernet0/0

switchport access vlan 2

!

interface Ethernet0/1

!

interface Ethernet0/2

!

interface Ethernet0/3

!

interface Ethernet0/4

!

interface Ethernet0/5

!

interface Ethernet0/6

!

interface Ethernet0/7

!

passive FTP mode

clock timezone IS - 5

DNS server-group DefaultDNS

domain energy.com

access-list 101 extended allow ip 10.0.0.0 255.255.255.0 192.168.150.0 255.255.255.0

access-list sheep extended ip 10.0.0.0 allow 255.255.255.0 192.168.150.0 255.255.255.0

outside_in list extended access permit tcp any host 74.x.x.146 eq 35330

outside_in list extended access permit tcp any host 74.x.x.147 eq 10000

outside_in list extended access permit icmp any one

outside_in list extended access permit tcp any host 74.x.x.148 eq 990

outside_in list extended access permit udp any host 74.x.x.148 eq 900

outside_in list extended access permit tcp any host 74.x.x.148 4000-4099

access-list extended outside_in permit udp any host 4000-4099 74.x.x.148

outside_in list extended access permit udp any host 74.x.x.148 eq 990

pager lines 24

Enable logging

timestamp of the record

exploitation forest-size of the buffer of 100000

debug logging in buffered memory

asdm of logging of information

Within 1500 MTU

Outside 1500 MTU

IP local pool dhcppptp-192.168.150.1 - 192.168.150.20

ICMP unreachable rate-limit 1 burst-size 1

ASDM image disk0: / asdm - 524.bin

don't allow no asdm history

ARP timeout 14400

Global 1 interface (outside)

NAT (inside) 0 access-list sheep

NAT (inside) 1 10.0.0.0 255.255.255.0

NAT (inside) 1 0.0.0.0 0.0.0.0

public static 74.x.x.146 (Interior, exterior) 10.0.0.90 netmask 255.255.255.255

static (inside, outside) 74.x.x.147 10.0.0.91 netmask 255.255.255.255

public static 74.x.x.148 (Interior, exterior) 10.0.0.3 netmask 255.255.255.255

Access-group outside_in in external interface

Route outside 0.0.0.0 0.0.0.0 74.x.x.145 1

Timeout xlate 03:00

Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00

Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00

Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute

GANYMEDE + Protocol Ganymede + AAA-server

RADIUS Protocol RADIUS AAA server

Enable http server

http 10.0.0.0 255.255.255.0 inside

http 192.168.1.0 255.255.255.0 inside

No snmp server location

No snmp Server contact

SNMP-Server Community public

Server enable SNMP traps snmp authentication linkup, linkdown cold start

Crypto ipsec transform-set esp-3des esp-md5-hmac RIGHT

Crypto dynamic-map cisco 1 transform-set RIGHT

dynamic dyn-map 20-isakmp ipsec crypto map Cisco

dyn-map interface card crypto outside

crypto ISAKMP allow outside

crypto ISAKMP policy 10

preshared authentication

3des encryption

md5 hash

Group 1

life 86400

crypto ISAKMP policy 30

preshared authentication

3des encryption

md5 hash

Group 2

life 86400

Telnet 10.0.0.0 255.255.255.0 inside

Telnet timeout 5

SSH 0.0.0.0 0.0.0.0 inside

SSH 0.0.0.0 0.0.0.0 outdoors

SSH timeout 5

Console timeout 0

TFTP server inside 10.0.0.109 cpix.cfg

internal BEVPN group policy

BEVPN group policy attributes

Server DNS 10.0.0.4 value 10.0.0.1

VPN-idle-timeout 30

Split-tunnel-policy tunnelall

Split-tunnel-network-list value 101

maindomain.com value by default-field

disable authentication of the user

IPSec-attributes tunnel-group DefaultL2LGroup

pre-shared-key *.

IPSec-attributes tunnel-group DefaultRAGroup

pre-shared-key *.

ISAKMP ikev1-user authentication no

tunnel-group BEVPN type ipsec-ra

attributes global-tunnel-group BEVPN

address-pool dhcppptp pool

Group Policy - by default-BEVPN

IPSec-attributes tunnel-group BEVPN

pre-shared-key *.

ISAKMP ikev1-user authentication no

!

class-map inspection_default

match default-inspection-traffic

!

!

type of policy-card inspect dns preset_dns_map

parameters

message-length maximum 512

Policy-map global_policy

class inspection_default

inspect the ftp

inspect h323 h225

inspect the h323 ras

inspect the rsh

inspect the rtsp

inspect esmtp

inspect sqlnet

inspect the skinny

inspect sunrpc

inspect xdmcp

inspect the sip

inspect the netbios

inspect the tftp

inspect the preset_dns_map dns

!

global service-policy global_policy

context of prompt hostname

Cryptochecksum:b379566df0e7f5213ad2396676763859

: end

Hello

I don't see the NAT0 configuration more in this configuration

NAT (inside) 0 access-list sheep

You can also change the ACL of Split Tunnel

standard access list permits 10.0.0.0 SPLIT-TUNNEL 255.255.255.0

BEVPN group policy attributes

no value of split-tunnel-network-list 101

Split-tunnel-network-list value of SPLIT TUNNEL

You can also use the "show run" command that will generate a little less production

-Jouni

Tags: Cisco Security

Similar Questions

  • When I try to add a VPN connection, I get an error that the wizard is unable to connect. I am running Windows Vista.

    When I try to add a VPN connection, I get an error that the wizard is unable to connect.  I am running VISTA. I want to simply add a VPN and be able to connect to a non-profit organization where I volunteer.  My VPN working two weeks ago.  Then my shortcut did not work, and this problem started.

    Any help is appreciated.

    original title: VPN Vista issues

    Hello

    Thank you for visiting the Microsoft answers community site. Your question of Windows Vista is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please post your question in the TechNet Windows Vista Networking forum.

    http://social.technet.Microsoft.com/forums/en-us/category/windowsvistaitpro

  • How can I find my username and password for Windows xp media center? don't remember setting but cannot get back in after the restart.

    How can I find my username and password for Windows xp media center? don't remember setting but cannot get back in after the restart.

    Hi Carol_971,

    1. Did you the latest changes on the computer?
    2. You have security software installed on the computer?

    Method 1

    I suggest that you try to start in safe mode and then try to log on to Windows using the default Administrator account and then remove the password for your account, check if it helps.

    A description of the options to start in Windows XP Mode

    http://support.Microsoft.com/kb/315222

    Method 2

    If you are unable to log on to Windows in safe mode, refer to the article below and then try the steps mentioned, check if it helps.

    How to connect to your Windows XP-based computer if you forget your password or if your password expires

    http://support.Microsoft.com/kb/321305

  • Cannot get CF11 to download the free trial version for students.  Anyone having the same problem with the Adobe site?

    Cannot get CF11 to download the free trial version for students.  Anyone having the same problem with the Adobe site?

    Hello

    Please download from http://www.adobe.com/cfusion/tdrc/index.cfm?product=coldfusion&promoid=DJDUK use your Adobe ID and password to login and download CF11.

    Let me know in the case where you are facing any problems during the download, if you get any error try another browser.

    Thank you

    Priyank

  • When I connect I get this icon in the menu: 'surely delete harware '.

    When I connect I get this icon next to my clock, when I click on it it pops up: remove the device safely. When I click on it, I'm going to another box: remove harware. In this box, I ask myself: select the device you want to unplug or eject, and then click on stop. When Windows notifies that it is safe to unplug the device from the computer. Equipment: USB Mass Storage Device. At location 0 USB storage device. It has a properties, Stop close button and a display device components.

    Whats up, doc? Why would I want to unplug anything? Device mass storge USB? OK, what I press?  Im just a contractor. I can build you a House, but cannot run a computer.

    Help

    Thank you Tim

    Hi Tim,.

    ·         Have you plugged a USB device on the computer while recording?

    ·         Did you do changes on the computer before the show?

    Perform a clean boot to see if there is a conflict of software like the clean boot helps eliminate software conflicts.

    How to configure Windows XP to start in a "clean boot" State

    http://support.Microsoft.com/kb/310353

    Note: After completing the steps in the clean boot troubleshooting, follow the section How to configure Windows to use a Normal startup state of the link to return the computer to a Normal startupmode.

    After the clean boot used to resolve the problem, you can follow these steps to configure Windows XP to start normally.

    (a) click Start, run.

    (b) type msconfigand click OK.

    (c) the System Configuration Utility dialog box appears.

    (d) click the general tab, click Normal startup - load all services and device drivers and then click OK.

    (e) when you are prompted, click on restart to restart the computer.

  • RV180 VPN connects and allows you to browse the files, but falls when opening a file.

    Last week, we received our 300Mbps fiber connection. We bought the RV180 due to its high performance, and he manages the speed perfectly.

    However, when you set up VPN, I encountered a strange problem.

    Establishing a QuickVpn or PPTP is simple and connection is no problem. But I'll be fine. I can communicate with QuickVpn or PPTP and find a NAS or PC directory structure, but when I try to open a file the VPC connection drops.

    I activate the remote management.
    I can ping google.com f-l 1472 without fragmentation, so a WAN MTU of 1500 should be ok.
    I have tried disabling attack prevention firewall.

    I have install the following experience: the firmware update (1.0.2.6), restore the default settings.

    Set up the RV180 as follows:

    IPv4 WAN (Internet)

    ------------------------------------------------------------------

    Internet connection type: Automatic Configuration - DHCP

    DNS Server Source: Get dynamically for ISP

    MAC address of the router: use the default address

    IPv4 LAN (local area network)

    ------------------------------------------------------------------

    Host name: RV180

    IP address: 192.168.75.1

    Subnet mask: 255.255.255.0

    Mode DHCP: DHCP Server

    Domain name: LCDVT

    From the IP address: 192.168.75.100

    End IP address: 192.168.75.254

    Rental time: 24

    DNS Proxy: enable

    Preventing attacks

    ------------------------------------------------------------------

    WAN (Internet) security controls

    Meet Ping on WAN (Internet): disabled

    Stealth mode: disabled

    Floods: disabled

    LAN (local area network) security controls

    Block UDP Flood: disabled

    Parameters of the ICSA

    Block the anonymous ICMP Messages: disabled

    Block fragmented packets: disabled

    Block multicast packets: disabled

    VPN users

    ------------------------------------------------------------------

    PPTP server: enabled

    From the IP address: 192.168.75.50

    End IP address: 192.168.75.99

    Table setting VPN Client:

    ---------------------------

    No: 1

    Enabled: enabled

    Username: lcdvt

    Password: *.

    Allow the user to change the password: NA

    Protocol: PPTP

    Web access

    ------------------------------------------------------------------

    Access on the LAN of HTTPS Web Interface: enabled

    Remote management: enabled

    Type of access: IP range

    Start of range: 192.168.75.1

    End of series: 192.168.75.254

    Port number: 443

    Remote SNMP: disabled

    The rest of the menu options are, except for logging policies where I have everything turned on by default.

    In this experiment, I connect from a remote location, start navigating among directories of the drive without any problems and then open a file, after which the VPN connection falls (or some process breaks down). After the transfer of a few 100 KB blocks the VPN connection.

    Error logs

    ------------------------------------------------------------------

    Thu Mar 20 00:39:18 2013(GMT+0100) [rv180] nimfNetIfaceTblHandler [System] [NIMF]: could not get LedPinId

    Thu Mar 20 00:39:25 2013(GMT+0100) [rv180] [System] [PROGRAM] IP: 62.45.238.236

    Thu Mar 20 00:39:25 2013(GMT+0100) [rv180] [System] [PROGRAM] BCAST: 62.45.239.255

    Thu Mar 20 00:39:25 2013(GMT+0100) [rv180] [System] [PROGRAM] subnet: 255.255.254.0

    Thu Mar 20 00:39:25 2013(GMT+0100) [rv180] [System] [PROGRAM] GW: 62.45.238.1

    Thu Mar 20 00:39:25 2013(GMT+0100) [rv180] [System] [PROGRAM] DNS1: 62.45.45.45

    Thu Mar 20 00:39:25 2013(GMT+0100) [rv180] [System] [PROGRAM] DNS2: 62.45.46.46

    Thu Mar 20 00:39:25 2013 (GMT + 0100) [rv180] [System] [PROGRAM] Interface: eth1

    Thu Mar 20 00:39:32 2013(GMT+0100) [rv180] nimfNetIfaceTblHandler [System] [NIMF]: could not get LedPinId

    Thu Mar 20 00:40:58 2013(GMT+0100) [rv180] nimfNetIfaceTblHandler [System] [NIMF]: could not get LedPinId

    Thu Mar 20 00:41:10 2013(GMT+0100) [rv180] [System] [PROGRAM] IP: 62.45.238.236

    Thu Mar 20 00:41:10 2013(GMT+0100) [rv180] [System] [PROGRAM] BCAST: 62.45.239.255

    Thu Mar 20 00:41:10 2013(GMT+0100) [rv180] [System] [PROGRAM] subnet: 255.255.254.0

    Thu Mar 20 00:41:10 2013(GMT+0100) [rv180] [System] [PROGRAM] GW: 62.45.238.1

    Thu Mar 20 00:41:10 2013(GMT+0100) [rv180] [System] [PROGRAM] DNS1: 62.45.45.45

    Thu Mar 20 00:41:10 2013(GMT+0100) [rv180] [System] [PROGRAM] DNS2: 62.45.46.46

    Thu Mar 20 00:41:10 2013 (GMT + 0100) [rv180] [System] [PROGRAM] Interface: eth1

    Thu Mar 20 00:41:19 2013(GMT+0100) [rv180] nimfNetIfaceTblHandler [System] [NIMF]: could not get LedPinId

    Warning logs

    ------------------------------------------------------------------

    Thu Mar 20 00:39:13 2013(GMT+0100) [rv180] [System] [DHCPC] dhcpcDisable: removed dhclient.leases

    Thu Mar 20 00:40:54 2013(GMT+0100) [rv180] [System] [DHCPC] dhcpcDisable: removed dhclient.leases

    Sat 1 Jan 01:02:43 2011 (GMT + 0100) [rv180] [Kernel] [KERNEL] [23.090000] /home/aruns/rv180w/updated_dec19_final/beta-v1/rv180w-common/comps/gpl/ipset/src/ipset/kernel/ip_set.c: ip_set_create: no type set 'nethash', 'setPublicNet' has not created value

    What I am doing wrong? Or the device?

    I am interested in what the solution to these problems.  Research on get a rv180...

    First car of Huntsville and bike e-magazine: www.huntsvillecarscene.com

  • ASA VPN connection cannot see all subnets

    I'm new to the ASA and I have a problem with our remote users. When people access vpn, they don't see a couple subnets on the network. I looked at the ASA and he can see and communicate with subnets, but when you vpn in them is not reachable. All these connections are connections from admin to admin privlages. Anyone know why the ASA can see subnets, but the admin vpn users cannot?

    You compare your ACL split tunnel and your table routing, but only for networks that are relevant to you and you must have access to and are not outside the old configuration. You should also ensure that these networks can route traffic from the pool of vpn.

  • Cannot get new url of the tab open with the homepage (Google).

    After the upgrade, I cannot get rid of 12 boxes (Facebook, Youtube, etc.) on the new tab or make open with my homepage (Google). I tried two different newtaburl add-on, uninstall and reinstall Firefox and the directives of the object: subject: config, browser.newtab.url, etc. I can't even scratch try this approach. I can't get the 12 bar blues.

    Well, I know I'm repeating something you've read before, but just for completeness (and also, I suspect this isn't built-in Firefox page):

    (1) in a new tab, type or paste Subject: config in the address bar and press ENTER. Click on the button promising to be careful.

    (2) in the search above the list box, type or paste newtab and make a pause so that the list is filtered

    (3) double-click the preference browser.newtab.url and enter your favorite page:

    • (Default) page thumbnails = > subject: newtab
    • Blank tab = > subject: empty
    • Built-in Firefox homepage = > topic: welcome
    • Any other page = > full URL of the page

    Press Ctrl + t to open a new tab and check that it worked. Fixed?

    Some traps:

    If Firefox will not let you change this setting: you can have what is called SearchProtect on your system.

    Firefox if allows you to save your changes, but he doesn't know: one of your extensions may be the substitution of her. You can consult, disable and/or remove extensions on page modules. Either:

    • CTRL + SHIFT + a
    • "3-bar" menu button (or tools) > Add-ons

    In the left column, click on Extensions

    If the modification works during your session, but during the next startup is return to the unwanted page: you could have a user.js file in your personal settings Firefox (your Firefox profile folder). This article describes how to track down and delete the file: How to fix preferences that will not save.

    A little luck?

  • QuickVPN connected, but I can't do anything on the LAN ping

    Hi all

    I try to use QuickVPN to connect to my corporate network. Yesterday I was to the point where QuickVPN actually connected and I could connect to the router from inside IP. But I can't see, or ping all computers on the LAN to company. Manual of the router says '' customer QuickVPN may access only the default LAN hosts. ''. Are the computers of the default of the company LAN LAN hosts?

    I added the router (RV220W) to the existing company LAN to test QuickVPN. The company LAN has a Small Business Server as a DHCP server and another router as the default gateway. The company LAN the subnet 192.168.1.0/24*, the cisco wan router has the subnet 192.168.103.0/24 and my VPN client is connected to a hotspot wifi with the same wan and LAN 192.168.3.0/24. The LAN of the cisco router address is 192.168.1.1.

    * I know now, 192.168.1.0/24 is the worst possible choice for a net business, but I didn't when I installed the Small Business Server. I'll try to change it to something like 10.123.45.0/24 later.

    Thanks in advance
    Mike

    Hello

    You can reach a PC in the LAN of RV220, because the default gateway is not RV220.

    This is what happens: the PC with fast VPN (for example IP: 192.168.103.10) is ping a PC with IP 192.168.1.10, via the VPN tunnel. Once the request arrives at the 192.168.1.10 PC, this PC sends the response to its default gateway (because don't have a direct connection to the 192.168.103.X network). If the default gateway is RV220, he'll know that the response should be returned via the VPN tunnel to the customer, but if it's another machine, it will just drop the package.

    In this case this another router (default gateway) must be configured with a static route, saying that subnet 192.168.103.x has as default gateway - 192.168.1.1 (RV220).

    As long as the IP address of the VPN machine fast is the same, it's ok. But if you move this PC to another local network, you will have again the problem.

    So if you plan to change the LAN IP of the fast VPN machine, I recommend using instead the Shrew VPN, where you can configure virtual IP on the client, that does not need to change.

    Kind regards

    Bismuth

  • Win 7 VPN client cannot access remote resources beyond the VPN server

    I have a Win 7 laptop with work and customer Win 7 VPN set up, and through it that I can access everything allowed resources on the remote network.

    I built a new computer, set up the Win 7 client with the exact same parameters everywhere, connected to the VPN with success, but can not access any of the resources on the remote network that I can on my laptop.

    Win 7 64 bit SP 1

    I did research online and suggestions have already had reason of my new set up.  In addition, I have a second computer that I've set up the VPN client, and I'm having the same problem.  VPN connects successfully, but is unable to access the resources.

    Tested with firewall off the coast.

    Troubleshooting Diagnostic reports: your computer seems to be configured correctly, distance resources detected, but not answered do not.

    I created another VPN client on the new computer to another remote network and everything works perfectly.

    Remember the old VPN connection to the remote network that does not work on the new computer works perfectly on Win 7 64 bit laptop computer.

    So, what do I find also different between identical configurations "should be" where we work and two new machines is not?

    It must be something stupid.

    Hello

    This question is more suited for a TechNet audience. I suggest you send the query to the Microsoft TechNet forum. See the link below to do so:
    https://social.technet.Microsoft.com/forums/Windows/en-us/home?Forum=w7itpronetworking

    Please let us know if you have more queries on Windows.

  • Cannot get my pictures in the order I want.

    I can't get my photos in the order I want.  I do this:

    (1) select the photos I want in the main file using a color filter. Then, I select the filter to display a selection of photos.

    (2) I rearrange the photos in the order I want by drag-and - drop in the "film" at the bottom of the screen.

    (3) I select the photos newly built for export. If I export to a new file the new photos in the new reveert file to the old order. Strangely, if I have the cursor on the images of the film of the new file, they are numbered in my custom command but physically they were returned back to the order that they were in before I gave up and dragged.

    What should I do on custom order my photos and export them to a new file that will recognize this order? I've done this plenty before but suddenly something goes wrong.

    Thank you

    Craig

    LR by default to capture the time - are you by selecting the command file name in the toolbar?

  • VMware workstation 8 briged connection cannot get an ip address from the dhcp server

    Hello, I hope someone can help me with this problem, my virtual machines are unable to obtain an ip address from my dhcp server in windows server 2008R2.

    VMware workstation 8 is running in windows 7 proff. 64-bit OS. My gets physical computer an ip Server dhcp without problem have access to the internet and everything works fine, but my VMs for some reason any cannot obtain an ip address from the DHCP server.  I updated virtual nework Briged editor one of my physical network interface cards. Then I put my VM NIC to briged in for some reason my VMs are unable to obtain an ip address. The ips only I get are 169.254.43.129 Add 255.255.0.0. any help would be very happy. Thank you very much.

    FYI - you have posted some of the vmware.log

  • iPhone - ASA VPN connects and gets disassembly

    Hello world...

    I have a VPN working properly on a 8.0 (5) ASA, but when I try to connect from an iPhone (IOS 5.1.1) it connects and immediately Gets a teardown.

    Any thoughts?

    Thank you!

    can you pls share your config ASA and advise what group policy, you use for iphone users?

  • Cannot get active document when the user clicks on the document in Adobe FM 2015.

    I am facing the following problem:

    I have a timer in my application that strikes several times after 2 seconds to get the name of the current document (if there is).

    If the user selects text (the click of the mouse down) of the current document in Adobe FM 2015 then the following API call returns 0 (which is false):

    F_ApiGetId (FV_SessionId, FV_SessionId, FP_ActiveDoc)

    Later, if the user leaves the mouse (click of the mouse to the top) then in the next hit of the timer the document name is extracted.

    It seems that the Adobe FM 2015 cannot manage simultaneously the two entries of the user of the application and the API in my application calls.

    Why is this happening?

    It seems that Adobe FrameMaker 2015 cannot handle at the same time user UI events and FDK API calls from external applications.

    When user interacts with the application FM calls API FDK for my failure in the external application with error codes.

  • Lost and confused... .cannot get LR to find the catalog.

    I recently managed to corral all of my photos one a LaCie Rugged hard drive. It is the reader where I intend to keep my LR photos to have portability. As I have all my pictures on HD, as I did on the iMac running the latest available software, I changed the name of the catalog to "My Photos Lightroom"

    that are stored on the drive that is labeled "LaCie Photos".  After you get them on the LaCie during the same session, I was able to view them without problem.  Okay, I take the drive and connect it to my MacBook Pro, running the same operating system.  LR could not find the catalog.  I tried several 'remedies', which none worked.  I went back to look at the catalogue on the iMac to see how it has been configured so that I could do the same thing on the MacBook and iMac could not find the catalog.  Until I really mess up things I'd rather have someone more competent as me give me some simple advice.  Summary: How do running on an iMac and a MacBook Pro to locate and use the catalogue of pictures of LR

    Located on a portable LaCie Rugged hard drive?  I don't know that I placed the catalog where it should not be lost on the path to the catalog. I need to give specific instructions to the computer and I don't seem to be able to do.  Thanks for any help you can give.

    GCR49... I think you are making things very difficult for yourself.

    Why don't you start by putting your photos on the EHD, creating the catalog on the pictures on the EHD? In this way, you don't have to transfer the pictures later to SMT. In addition, file-> new catalogue allows you to create a catalog on the EHD.

    Do not... Are NOT... do multiple catalogs. "Subsequently, with much more practical, experience and focus I can decide to multiple catalogs if necessary" is a very bad idea, except in a very limited situations. Do not forget this.

Maybe you are looking for