VPN site to site many of the same facilities

Hello

I have a Cisco ASA 5510 in my central site. I created a VPN to connect to a remote site that has a draytek 2830.

Because some particularities to include other networks in that vpn.

We must therefore from the remote site to comunticate with more than one network.

For example:

Network: 192.168.1.0/24, 192.168.2.15/32, and 192.168.3.15/32

The only solution I found was to create a vpn on the draytek for each network connection. On the side of Cisco, I also created a connectio for each network.

The VPN feature if they start in a determined order. If the vpn for the 192.168.1.0 network starts first them there is no traffic...

Can you please help me.

Best regards.

Hi João,.

On the SAA, we can create a map encryption for ip address a peer.

According to my understanding, it seems that you try to configure crypto different cards for different networks on the other side.

On ASA, to set it up following the path: -.

Acccess-list allowed test ip 192.168.1.0 255.255.255.0

Acccess-list test permit ip host 192.168.2.15

Test permit ip host 192.168.3.15 acccess-list



map 1 set testmap crypto peer

test card crypto testmap 1 match address

card crypto testmap 1 game transform-set ESP-3DES-SHA.

Let me know if it helps.

If possible, join the running of your ASA configuration as well.

Kind regards

NGO

Tags: Cisco Security

Similar Questions

  • about to buy a video.  It contains options for speed on the overview of the site, do get the same options to slow down the video down when I buy the video?

    about to buy a video.  It contains options for speed on the overview of the site, do get the same options to slow down the video down when I buy the video?

    The videos is not 'options '. They are exactly as described. You can use first to add slowed to any video. Correction of the one who is already slowed to normal speed may not produce get results.

    But to answer the question, the videos are exactly as in preview. It would be to you on how you change them and with which application.

  • ASA5505-Site-Site & RA on the same device

    Howdy all,

    I am trying to set one up for a VPN site to site and remote access.  Site-to-site works fine, however when I connect using the Cisco client, after the password and the initial connection calls I get a State "not connected".  The log shows that a political card match is not found.  I have successfully set the unit for remote access with any site-to-site and has faced another set of issues when adding the website-site for the configuration of remote access to work, so I started during the implementation of site to site first.  I tried this through ADSM (hate) - the current configuration is a cli.  Any thoughts would be appreciated, I am sure that Miss just a piece or two.

    ASA Version 8.2 (5)
    !
    ASA5505 hostname
    activate the encrypted password of XXXXXXXXX
    passwd encrypted XXXXXXXXX
    names of
    192.168.0.0 MainOffice name
    name 192.168.251.0 RAAddresses
    name of 10.10.10.0 MainSiteIP
    !
    interface Ethernet0/0
    switchport access vlan 2
    !
    interface Ethernet0/1
    !
    interface Ethernet0/2
    !
    interface Ethernet0/3
    !
    interface Ethernet0/4
    !
    interface Ethernet0/5
    !
    interface Ethernet0/6
    !
    interface Ethernet0/7
    !
    interface Vlan1
    nameif inside
    security-level 100
    IP 192.168.1.1 255.255.255.0
    !
    interface Vlan2
    nameif outside
    security-level 0
    IP 192.168.250.147 255.255.255.0
    !
    passive FTP mode
    access-list 101 extended allow ip 192.168.1.0 255.255.255.0 255.255 MainOffice.
    255.0
    access-list 101 extended allow MainOffice 255.255.255.0 ip 192.168.1.0 255.255.
    255.0
    access-list 102 scope ip allow a whole
    access-list 102 extended allow MainOffice 255.255.255.0 ip 192.168.1.0 255.255.
    255.0
    access-list 103 extended allow ip RAAddresses 255.255.255.0 192.168.1.0 255.255
    . 255.0
    access-list 103 extended allow ip 192.168.1.0 255.255.255.0 255.255 RAAddresses
    . 255.0
    pager lines 24
    asdm of logging of information
    Within 1500 MTU
    Outside 1500 MTU
    IP pool local RAPool 192.168.251.100 - 192.168.251.120
    no failover
    ICMP unreachable rate-limit 1 burst-size 1
    don't allow no asdm history
    ARP timeout 14400
    Global 1 interface (outside)
    (Inside) NAT 0-list of access 101
    NAT (inside) - 0 103 access list
    NAT (inside) 1 0.0.0.0 0.0.0.0
    Access-group 102 in the interface inside
    Route outside 0.0.0.0 0.0.0.0 192.168.250.1 1
    Timeout xlate 03:00
    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    Floating conn timeout 0:00:00
    dynamic-access-policy-registration DfltAccessPolicy
    Enable http server
    http 192.168.1.0 255.255.255.0 inside
    MainOffice 255.255.255.0 inside http
    No snmp server location
    No snmp Server contact
    Server enable SNMP traps snmp authentication linkup, linkdown cold start
    Crypto ipsec transform-set esp-aes-256 CryptoSet, esp-sha-hmac
    Crypto ipsec transform-set esp-3des esp-sha-hmac RA
    life crypto ipsec security association seconds 28800
    Crypto ipsec kilobytes of life - safety 4608000 association
    Crypto-map dynamic dyn1 1jeu transform-set RA
    correspondence address 1 card crypto outsidemap0 101
    outsidemap0 card crypto 1jeu peer MainSiteIP
    outsidemap0 card crypto 1jeu transform-set CryptoSet
    outsidemap0 interface card crypto outside
    dynamic mymap 100 dyn1 ipsec-isakmp crypto map
    crypto ISAKMP allow outside
    crypto ISAKMP policy 10
    preshared authentication
    aes-256 encryption
    sha hash
    Group 2
    life 3600
    crypto ISAKMP policy 100
    preshared authentication
    3des encryption
    sha hash
    Group 2
    life 43200
    VPN-addr-assign local reuse / time 5
    Telnet 192.168.1.0 255.255.255.0 inside
    Telnet timeout 60
    SSH timeout 5
    Console timeout 0
    dhcpd outside auto_config
    !
    dhcpd address 192.168.1.5 - 192.168.1.254 inside
    dhcpd allow inside
    !

    a basic threat threat detection
    Statistics-list of access threat detection
    no statistical threat detection tcp-interception
    WebVPN
    attributes of Group Policy DfltGrpPolicy
    value of VPN-filter 101
    encrypted user user1 password IQM/O64OATR4zXx7 name
    tunnel-group MainSiteIP type ipsec-l2l
    IPSec-attributes tunnel-group MainSiteIP
    pre-shared key *.
    type tunnel-group RAGroup remote access
    attributes global-tunnel-group RAGroup
    address pool RAPool
    IPSec-attributes tunnel-group RAGroup
    pre-shared key *.
    !
    class-map inspection_default
    match default-inspection-traffic
    !
    !
    type of policy-card inspect dns preset_dns_map
    parameters
    maximum message length automatic of customer
    message-length maximum 512
    Policy-map global_policy
    class inspection_default
    inspect the preset_dns_map dns
    inspect the ftp
    inspect h323 h225
    inspect the h323 ras
    inspect the rsh
    inspect the rtsp
    inspect esmtp
    inspect sqlnet
    inspect the skinny
    inspect sunrpc
    inspect xdmcp
    inspect the sip
    inspect the netbios
    inspect the tftp
    Review the ip options
    !
    global service-policy global_policy
    context of prompt hostname
    no remote anonymous reporting call
    Cryptochecksum:07120668869a94278df931162ae4d7a5
    : end

    Hello Robert,.

    IP pool local RAPool 192.168.251.100 - 192.168.251.120

    permit 192.168.1.0 ip access list No_NAT_RA 255.255.255.0 192.168.251.0 255.255.255.0

    no nat (inside) - 0 103 access list

    NAT (inside) 0-list of access No_NAT_RA

    attributes of Group Policy DfltGrpPolicy

    no value of vpn-filter 101

    access-list standard Split allow 192.168.1.0 255.255.255.0

    internal group R_A strategy

    value of group-lock RAGroup

    Protocol-tunnel-VPN IPSec

    Split-tunnel-policy tunnelspecified

    Split-tunnel-network-list value Split

    Kind regards

    Julio

  • several users, Web site editing at the same time

    If the site is registered under the names of different files, both users can have it open at the same time, but is there a way for each of them to edit pages and synchronize all

    each person changes their version of the page and it's going to happen first. order, which is really for the better when you think about it, first-served basis.

  • How can I stop Windows Update to install the same facilities again and again

    Why keep Windows Update install the same updates again and again

    Why keep Windows Update install the same updates again and again

    See: http://support.microsoft.com/kb/910339 -
    Troubleshooting Windows Update or Microsoft Update when you are repeatedly offered an update

    Or in the alternative, notify us of updates and maybe we can move forward.

  • a site and on the same pix vpn remote access

    I was wondering if anyone had an example of configuration, pix running 6.3 (4).

    He attached in pdf format

  • How to activate a blocked addon or Plugin to view the Web site and content the same as IE

    I use a Java Plugin to run a java applet used to my work. Google Chrome has been recently supported by this plugin, I have clients who are unable to work in Internet Explorer and would like to offer them an alternative.

    I can only do so if all the features of my site works in Firefox. Currently, there are a few display issues experienced in Chrome and Firefox with the site. Only IE it appears correctly.

    Should this site Web the Java Deployment Toolkit plugin?
    Or just the main Java plugin?

    If the first, the best you can do is to tell your users to use 'ask to activate' for the plugin. Oracle has never corrected the flaws of Security reported with this plugin of deployment for a couple of years now; Firefox will not allow him to activate automatically when the user has even the latest, updated version of Java installed.

    Here are a few items of support that might help you a little.
    https://support.Mozilla.org/en-us/KB/how-allow-Java-trusted-sites
    https://support.Mozilla.org/en-us/KB/why-do-i-have-click-Activate-plugins

    Java is basically dead for all purposes useful otherwise than for Oracle applications. And Oracle work better on their own web browser for all platforms or Oracle business applications will appear on the tombstone with Java. I'm curious what will be their joint epitaph.

  • Protect a remote site run by the same VC Server

    Hi guys,.

    We have a small site in New Zealand, we want to protect through RS, but it doesn't have its own VC server, as I manage it since the server VC here in Australia.

    If I build a SRM server in New Zealand that create a new site on my server VC and allow me to protect virtual machines NZ here?

    As far as I know, you can have 3 way under SRM protection. You need to replicate VMs to Brisbane of NZ and register them manually on the server vCenter failure. How can VMs are there in New Zealand?

    Thank you

  • My containers page exactly in the same place on each page do not sit!

    Hello

    I created a site with four named pages

    HOME PAGE | SERVICES | LINKS | CONTACT

    My HOUSE and LINKS containers sit exactly in the same place, but when I go to SERVICES and communicate WITH the container is located slightly to the left of the other 2 pages.

    Have no idea why this would be?

    My site is still in development so the temporary address and missing content, here is the link

    http://ateccomputerservices.zxq.NET/index.html

    Thank you

    Maybe what you see is the appearance of a vertical scroll bar on long pages and the lack of one on the short pages - where the 'shift '.

    Add this to the top of your main CSS style:

    HTML {overflow - y: scroll}

    Nancy O.
    ALT-Web Design & Publishing
    Web | Graphics | Print | Media specialists
    http://ALT-Web.com/
    http://Twitter.com/ALTWEB

  • VPN Site to Site and remote access

    I have ASA certified with 25 concurrent VPN connections. I want to know if I have 20 remote tunnels and 5 Site-to-Site created on the same time tunnels, and I want to establish the new Site to the other tunnel, is him Site to Site remove the remote tunnels or can not put in place. Site at tunnels have a higher priority than the remote access or they are the same. Site at tunnels are more important to me and I need them to repress the remote access tunnels.

    Hello

    Sorry for the confusion. No you can not set the parameter like this.

    Thank you

    Gilbert

  • Impossible to establish VPN Site to Site

    Hi guys, please guide me in the right direction. Had difficulty getting VPN Comms for weeks now. State of VMware Support all well on their side and my guy of networking in the field say the same thing.

    I should mention that we did with success of VPN to AWS and Azure from the same site on Prem.

    I can't establish an East / West comms, no not even ICMP between VCC on prem and AIR nodes. but has been able to set up Internet with virtual machines in vCA (North/South)

    My VPN status on edge gateway services is RED (no access) but activated. I checked the settings on our other clouds that work, and the config looks the same.

    Things I go back on >

    * Peer IP > when setting this up, vCA says "If the peer is NAT would be, this must be the public side address NAT.»

    * Local end point > IP listed in the config file is listed as FREE under bridge details, why would it be free if it is assigned to the VPN session?

    * Makes the following two actions, when you look at Masters edge gateways? Re-apply a Configuration of Service and redeploy? I want to reset my edge session, do not drop the settings.

    As the I understand, I won't need any particular rule of SNAT to be able to do a ping on VCC prem nodes / or upstream? is that correct?

    Any help would be greatly appreciated, it's reflecting well on the AIR, whereas the AWS and Azure worked the 1st time.

    He ends up being the 3rd party business networking that has implemented the ASA on Prem. Almost doubted vCA :-)

  • Once ubuntu was last updated for firefox installed, MarketWatch site displays only the mobile site

    After that the latest patches installed (including updates of Firefox) Ubuntu http://www.marketwatch.com always displays the site www.marketwatch.com/m

    For some reason any marketwatch thinks I'm on a mobile device

    It is a problem on the MarketWatch site - I see the same result in Firefox on Ubuntu. I sent an email to their feedback address and will post here if / when they respond.

  • Windows IPSEC and SSL VPN client on the same machine

    Matches (coexistence) installation of IPSEC and SSL vpn clients that are supported on the same computer, windows (XP and Win7)?

    As mentioned by Patricia and Jennifer (5 stars), you can install two clients on the same machine without any problem.

    The tricky part comes when you are trying to connect two clients at the same time, that's when you may encounter unexpected problems.

    However, if your intention is to install both clients and connect them individually and not at the same time, you'll be fine.

    If you have any other questions, please mark this question as answered and note all messages that you have found useful.

    Thank you.

    Portu.

    Post edited by: Javier Portuguez

  • How can I disable the Switch-to-Tab function? -I need to open multiple tabs in the same place...

    I need to keep several versions of the same site opened at the same time, and then switch between them... Apparently the Switch-to-Tab function will not allow this and keep my duplicated tabs become other Web pages...

    You can turn it off by using the switch to tab no Add on more - https://addons.mozilla.org/firefox/addon/switch-to-tab-no-more

  • Photosmart B8550 - make the XL 564 cartridges ink also incorporate the same print head?

    Photosmart B8550

    XL 564 ink cartridges sit also in the same print head? Or do I need to buy a big print head to accommodate XL ink cartridges?

    I ask this is because 564 plain ink cartridges seem to fit pretty snuggly here, so I don't see how a wide range of ink cartridges could go in there!

    Or what is the standard ink cartridges are only half full and XL ink cartridges are full, so they use the same ink cartridge?

    Thank you!

    As long as you use the same number 564, etc. 940 XL just means that it gives more volume page. So, you can use the same print head...

Maybe you are looking for

  • Only 2 available ram slots, not 4 on 27 inch Mid 2010 iMac i3

    Hello Well, I'm puzzled.  I bought an iMac 27 inch, Intel Core i3 mid2010 news about 5 years ago. In the about this Mac it says 4 slots available, with only 2 in use (2 GB each).  This week I took it to a technician to install additional RAM and we d

  • Unable to backup on drive F or deletion of the D drive.

    When I try a backup of my F drive, the program uses by default the D drive (which is now complete.  I tried repeatrdly to backup the disk F stand alone without success.  Also I don't know the way to delete the files from D drive. I use a laptop Dell

  • Laptop freezes and then stop.

    Log name: SystemSource: Service Control ManagerDate: 15/07/2016-09:49:55Event ID: 7024Task category: noLevel: errorKeywords: ClassicUser: n/aComputer: PC-userDescription:The Windows Search service terminated with service specific error %-2147418113.T

  • Sharing the burden of the IDS/IPS

    Hi experts, Since it is possible to implement some IDS features on routers and PIX, along with the ID is, in a network where all 3 of these devices exist, is it interesting to implement some features on routers and PIX IDS? And, if so, what factors a

  • AAA to circumvent the password to enable on the Cisco ASA

    Hi all. I'm having a problem where I get authenticated by the AAA server, but after authentication, that I am placed in user mode. AAA admin (I have no access to the AAA server) told me that he had all the users configured with priv level 15, which w