Cisco VPN :: 5510 - Site-to-site IPsec VPN / ASA To IOS And Redundant ISPs?

Oct 3, 2012

Site A has an ASA 5510 and a single internet connection.Site B has two internet connections (primary and backup). If Site B also has an ASA, I can configure Site A's ASA to deal with a failover at Site B (set peer Does this work if Site B has an IOS router instead of an ASA? In other words will "set peer" on the ASA work when it's talking to IOS on the other end?

View 15 Replies


Cisco VPN :: Redundant Site To Site VPN Peers ASA 5510

Oct 10, 2012

i have the topology below :
RX========== <sw 2960g>==========(Gi0/1)(Gi0/2)Gateway 1 ============>internet
                          Cache server  

Now from RX the traffic is out , it may go to Gateway1 router or Gateway2 router
Note that router Gateway 1 has its traffic cached by Cache server. But the Gateway 2 router has not configured to cache its traffic , note that Gateway 1 router has two interfaces connected with sw   but Gateway 2 only 1 interface connected to sw .
In the end , if I want Router Gateway 2 to  hve its traffic to be cached by cahce server , can I do as the same config which is currently exist in Gateway 1   , or there is different behaviuor ???? Is there new modification on cahce server ?? im using suid cahe based linux .
I will include a brief info about only cache config in gateway1 router
ip access-list extended CACHE5
deny   tcp any host x..x.x.x eq www
deny   tcp any host x.x.x.x
permit tcp x.x.x.x x.x.x.x any eq www
[Code] ........

Can I do the same config on router gateway 2 ?

View 2 Replies View Related

Cisco Security :: ASA 5510 - Site To Site IPSEc VPN Configuration Access List

Sep 12, 2011

I configurated Ipsec vpn at asa 5510. my inside ip public ip: 85.x.x.xmy peer ip : 62.x.x.x
the project is that:
the remote site want the interesting traffic like that:
source ip can access destination ip

My inside ip is and i can not to change it and i can not to add this ip at my network.

View 3 Replies View Related

Cisco VPN :: ASA 5505 To 5510 Site-to-Site VPN IPSec Don`t Go

Sep 29, 2012

I just try to build a Site-to-Site VPN over IPSec between a ASA5505 and a ASA5510. But it don`t want to work. Here are the config`s of the ASA 5505 and ASA5510:
: Saved
: Written by enable_15 at 20:02:51.175 UTC Wed Apr 7 2010
ASA Version 7.2(2)
hostname asa5505
enable password 8Ry2YjIyt7RRXU24 encrypted

View 22 Replies View Related

Cisco VPN :: ASA 5510 Site To Site IPSec VPN And NAT

Aug 1, 2011

this is our scenario. We have one server We have an ASA 5510. This server is mapped to the outside world Our client has an ASA 5510. Their subnet is /24. We want to create a IPsec site to site VPN to and from them.Here's the catch. Our client already has a VPN tunnel to a customer of theirs who's subnet is /24.
is it possible to NAT to a second virtual IP? Then have that IP mapped thru the VPN to our client? That way they access the server via our server's SECOND NAT? Or am I not thinking outside the box?

View 8 Replies View Related

Cisco VPN :: 877 / How To IPsec Site To Site Vpn Port Forwarding To Remote Site

Jun 13, 2012

The scenario where a Site to Site VPN tunnel has been established between Site A and Site B. Lan on Site A can ping Lan on Site B. My problem is a Printer behind Site B needs to be accessed by using the WAN IP address of Site A. Also i could not ping the remote lan or printer from the router.
Below are my configure on the Cisco 877 in site A.  
Building configuration... 
Current configuration : 5425 bytes
! Last configuration change at 15:09:21 PCTime Fri Jun 15 2012 by admin01
version 12.4
no service pad


View 1 Replies View Related

Cisco VPN :: 5510 Site To Site VPN Access To Servers With Overlapped Remote Site

May 18, 2012

I have a requirement to create a site to site vpn tunnel on ASA 5510 from a remote site to my HO, ihave already other site-to-site tunnels are up and running on the ASA.The issue is my remote site has got the network address which falls in one of the subnet used in HO( requirement is only  My remote site need to accees couple of my servers in HO which is in subnet.

View 2 Replies View Related

Cisco Switching/Routing :: 1941 / K9 Unable To Ping Over Site To Site IPSEC

Jul 12, 2012

I am trying to set up a site to site ipsec connection. AT site A, I have Vlan's 652-, Vlan653 -, Vlan 654- and Vlan655- and at site B, Vlan650- and Vlan651- problem is that I am unable to get any associations when i do a "sh crypto isakmp sa"/"sh crypto ipsec sa" on either router at each site.I am also unable to ping by pluging in a laptop into the site at each site. Laptop at site A is set to access vlan 655 and laptop at site B is set to acess vlan 651. I can ping all the devices from one end to the other.I have turned on debug crypto isakmp, debug crypto ipsec, debug crypto ipsec errors but dont get anything at all as output.I have attached the sh run for each router Cisco (1941/K9) and switch (Catalyst 3750) at each site.

View 4 Replies View Related

Cisco Switching/Routing :: ASA 5525 - Configure Site-To-Site IPsec VPN To 3 Peers

Nov 21, 2012

I have an ASA 5525 and need to configure site to site ipsec vpn to 3 peers. I currently have an existing /28 public address from my ISP that is used by other services.Is there a way to use this existing ip range to configure IPSEC tunnels to 3 peers ?

View 10 Replies View Related

Cisco WAN :: 2911 - Site-to-site IPsec Vpn / Unable To Ping Remote Network

Apr 3, 2013

I have two Cisco routers - 2911 in HQ and RV180 in branch office. Because in HQ LAN network I have some development servers, to which guys from branch office need to have acces, I decided to setup VPN site-to-site between HQ and branch office. Everything went quite smoothly, on both devices I see, that ipsec connection is established. Unfortunately I am not able to ping resources from one network to other one and vice versa. Below is the configuration of 2911 router (I skipped som unimportant (imho) configuration directives) :
crypto isakmp policy 1
encr 3des
hash md5


View 9 Replies View Related

Cisco WAN :: AES-128 IPSEC Site-to-Site VPN Multiple Crypto Maps For One Peer

Jan 28, 2013

With à customer we have à site to site VPN connection. In this tunnel there is one subnet routed with a 3des-sha encryption / hash. Now the want to add a new subnet in this tunnel, but with a AES-128 / MD5 encryption / hash. Is it correct if we make a new crypto map with a higher seq. number?

View 5 Replies View Related

Cisco VPN :: Setup Site-to-Site Connection With 5505 ASA Using IPSec And Isakmp?

Aug 8, 2011

im drawing a blank trying to setup a site to site connection with a 5505 ASA using ipsec and isakmp.i have the pre shared key as well as the external address of the other end of the tunnel but do not remember what the commands are to setup the crypto map and isakmp.

View 7 Replies View Related

Cisco VPN :: ASA5505 - IP Address Pool In IPSec Client And Site-to-site VPN

Jul 10, 2012

We have a scenario where the Cisco ASA 5505 will be one end of a site-to-site VPN. The same ASA 5505 also allows Client VPN connection. The question is around IP pooling. If I assign a pool of IP's ( - for Client VPN connections - do I need to be sure that those same IP's are not used on the other side of site-to-site VPN ?

There could be PC's/Servers running on the other side of site-to-site VPN. Would this cause an address conflict ?

View 4 Replies View Related

Cisco WAN :: 3825 Shared Internet Through Site To Site IPsec VPN Tunnel

Apr 24, 2013

I have configured Ipsec vpn tunnel beetween two routers (from site A to site B) over untrusted internet connection by cisco 3825 routers and i can  successfully access both of this routers. But now i need to access internet on site B router sitting on site A router. So that if i run traceroute from A site machine then the gateway by which internet passing through shows the ip of site B.

The Architecture of our both site routers :

Site A A tunnel----Router B B 

/////Create IKE policy
crypto isakmp policy 1
encr aes
authentication pre-share
group 2
[Code] .....

View 10 Replies View Related

Cisco VPN :: ASA5520 - Access-list For Site-to-Site IPSEC Tunnel

Dec 1, 2011

How can I NAT the same set of four hosts and give them access to two different networks across an IPSEC site-to-site VPN tunnel?  I'm using an ASA5520 running 8.04.
I have four hosts say:
They need access to two different networks:
I woud like to NAT them as something like: 

View 1 Replies View Related

Cisco VPN :: Establish Site To Site IPSec Tunnel Between ASA 5520 And 3030?

Feb 17, 2013

We have configured a site to site tunnel from our ASA to another organizations Cisco 3030.  It appears to have just one way initiation.  We can do a ping to a device on the remote site and it will ping just fine.  however, when the tunnel needs to be initiated from the remote site, it will not work until we have initiated the tunnel and then everything works.
I continue to see Error processing payload: Payload ID: 1 errors on the ASDM logs.It appears that all the configuration is in place because we can in fact establish the IPSec tunnel unidirectional.  And once established, traffic can flow bidirectional.

View 1 Replies View Related

Cisco VPN :: Site To Site VPN IPSEC Tunnel From ASA 5505 To Clavister Firewall

Nov 20, 2012

I have weird problem with a Site to site VPN tunnel from a Cisco ASA 5505 to an Clavister Firewall.When I restart the Cisco ASA 5505 the tunnel is up and down,up, down, down, and I get all strange messages when I see if the tunnel is up or down with the syntax: [code]
After a while like 5-10 min the vpn site to site tunnel is up and here is the strange thing happening I have all accesslists and tunnel accesslists right I can only access one remote network (Main site Clavister Firewall) trought the vpn tunnel behind the Cisco ASA 5505, and I have 5 more remote networks that I want to access but only one remote network is working trought the vpn tunnel behind the Cisco ASA. I see that when I do this syntax in ASA: show crypto ipsec sa.They had a Clavister Firewall before on that site before and now they have a Cisco ASA 5505 and all the rules on the main site thats have the big Clavister Firewall is intact so the problems are in the Cisco ASA 5505. [code]
All these remote networks are at the Main Site Clavister Firewall.

View 1 Replies View Related

Cisco VPN :: 4500 Switch - Dot1q Tunneling Via PPTP IPSec VPN Site-to-site Tunnel?

Nov 28, 2012

I have a situation where the site-to-site tunnel is already established using PPTP IPSec VPN with non Cisco Gateways terminating the link on each end. These non Cisco Gateways do not support L2TP tunneling, and there is no plan to change them.Beyond the Gateways on both ends, we have a Cisco 4500 series switch. We need to forward the 802.1q tagged VLANs between the two sites. Is it possible to use 802.1Q tunneling in this case, going via a PPTP tunnel ?
Cisco's setup uses dot1q-tunnel over a L2protocol-tunnel to preserve the original client VLAN tagging, so does this mean that the only option we have is to setup a L2TP tunnel at the Cisco device endpoints, and have that tunnel go through the existing PPTP tunnel (established between the 2 non Cisco VPN Gateways) ?

View 1 Replies View Related

Cisco WAN :: 3825 Internet Sharing By Ipsec Site To Site VPN

Apr 30, 2013

My requirment is Clients from site A should access the Internet from site  B (B will be providing internet to site A), So I have configured Ipsec vpn tunnel beetween two routers (from site A to  site B) over untrusted internet connection by cisco 3825 routers and i  can  successfully access both of this routers.I have configured a client machine in site A and configured gateway of this client is but dont have internet there.

View 2 Replies View Related

Cisco VPN :: Configuring IPsec Site-to-site VPN With 2911 Router

Mar 15, 2011

I have a Cisco 2911 router and a Cisco RV 120W router and i would like to establish a VPN tunnel between theese two. I have defined the settings on the Cisco RV 120W router and i just want the Cisco 2911 to follow those. setting up a connection with Cisco IOS.

View 1 Replies View Related

Cisco VPN :: Multiple Site To Site IPSec Tunnels To One ASA5510

Dec 4, 2012

Question on ASA VPN tunnels. I have one ASA 5510 in our corporate office, I have two subnets in our corporate office that are configured in the ASA in a Object group. I have a site to site IPSEC tunnel already up and that has been working. I am trying to set up another site to site IPSEC tunnel to a different location that will need to be setup to access the same two subnets. I'm not sure if this can be setup or not, I think I had a problem with setting up two tunnels that were trying to connect to the same subnet but that was between the same two ASA's. Anyways the new tunnel to a new site is not coming up and I want to make sure it is not the subnet issue. The current working tunnel is between two ASA 5510's, the new tunnel we are trying to build is between the ASA and a Sonicwall firewall.

View 3 Replies View Related

Cisco VPN :: TFTP From ASA Via Site To Site IPSEC Tunnel 5540

Nov 1, 2011

I am having issues getting my ASA 5540 at site A, to pass TFTP and SYSLOG from itself across the IPSEC tunnel to our SYSMON servers (Syslog and TFTP) that live at site B. I have followed the suggestions of other threads and I am still not getting anywhere. Here is a quick topology diagram.

View 6 Replies View Related

Cisco WAN :: 2800 How Many Site-to-site Ipsec Tunnel Without Vpn Module

Sep 20, 2011

Can i know cisco 2800 router can support how many site-to-site ipsec tunnel without vpn module?

View 2 Replies View Related

Cisco Firewall :: Pix 525 Site To Site IPSec Bandwidth Measurement

Oct 3, 2012

I have cisco pix connected at the edge of my GPRS network. Inside is the GPRS core network and outside is the ISP.On cisco pix, i have site to site IPSec configured between my inside GPRS network and Blackberry servers. for blackberry services.Using the ASDM I can see the total number of packets in and out on this site to site IPSec, but if I want to measure the trand of the bandwidth utilisation over this IPSec, per sec, then how can I do this? I have PRTG traffic monitoring, through which I did try, several MIB (listed below) but still not able to find the correct way. how can I get the measurement for the IPSec from cisco pix?

View 1 Replies View Related

Cisco VPN :: Site To Site IPSEc Tunnel Between ASA5520 And IPSO

Aug 10, 2011

I cannot get it to work : if interesting traffic comes ffrom the IPSO side, the box would not even try to set up the tunnel. and If it comes fomr the ASA side, the box attempts to do so but it with this strange message : AM_WAIT_MSG2

View 3 Replies View Related

Cisco VPN :: 5520 IPsec Site-to-Site VPN Multi-session?

Mar 14, 2011

I recently faced an issue at work. Clients want  to make ipsec site-to-site vpn redundant. I have 2-asa-5520 working in a stack. Is it possible to configure site-to-site vpn in a redundant mode, like first peer ip address is x.x.x.x and secondary is y.y.y.y (backup) ?

View 1 Replies View Related

Cisco WAN :: 2921 / Create Another Ipsec Site-to-site VPN Connection

May 11, 2013

currently I have a Cisco 2921 router and I have one active site-to-site VPN connection through the question is; how I can create another Ipsec site-to-site VPN connection ? I have to keep the 1st VPN connection active.

View 11 Replies View Related

Cisco VPN :: IPSec Site-to-Site Aggressive Mode On 1905

Dec 28, 2011

you can configure a cisco 1905 router with vpn ipsec site-to-site in an aggressive mode? If so, any link to what I do? The VPN works well, but on site A, I had to configure a crypto map associating the IP address for site B (wich is dynamic), so if the connection on site B broken, I will have to configure another crypto map.
The scenario is:

Site A - ASA 5510 configured as a VPN concentrator and firewall for enterprise.

Site B - Cisco 1905 connected to Internet through a ADSL through a dynamic IP address and starting connection to Site A, bellow is the configuration:
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key xxxxxxxxxxxx address W.X.Y.Z


View 2 Replies View Related

Cisco VPN :: Cannot Ping From Outside To Inside Site To Site IPsec 5505

Oct 28, 2012

I have a very basic lab site to site vpn setup where I have a ASA 5505 running v7.2(4) on one side and a cisco 2811 on the other side.

What's my issue?

I can't seem to ping from cisco router to the 'inside' network of ASA (see config below) and can't seem to ping from ASA packets leaving the 'inside' interface to cisco router even w/ an ICMP ACL permit outside in. However I'm able to ping within ASA inside network & ping cisco 2811 side w/ packets leaving ASA 'outside' interface just fine.
ciscoasa# ping inside (to cisco loopback1 from ASA inside)
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:

View 6 Replies View Related

Cisco VPN :: ASA5505 Site To Site IPSec VPN Will Not Connect

May 22, 2012

I've spent 2 days already trying to get 2 ASA 5505's to connect using an IPSec vpn tunnel. I cannot seem to figure out what im doing wrong, im using and as my internal networks that i'm trying to connect over a directly connected link on the outside interfaces with and as the addresses (all /24). I also tried with and currently without NAT enabled. Here are the configs for both ASA's, the vpn config was done by the ASDM, however i have also tried the command line apporach with no success. I have followed various guides to the letter online, starting from an empty config and from factory default. I have also tried the 8.4 IOS. [code]

View 2 Replies View Related

Cisco VPN :: 2921 Site-2-Site IPSEC VPN Tunnel Will Not Come Up

Dec 5, 2012

I am setting up a IPSEC VPN tunnel between a Cisco 2921 and ASA 550x. [code]

View 6 Replies View Related

Cisco VPN :: Site To Site IPSec Tunnel With Two 880 Routers?

May 9, 2012

I want a site to site vpn ipsec tunnel there wants to use two Cisco 880 routers that are connected to a modem / router is this possible?

View 12 Replies View Related

Cisco VPN :: Ipsec Site To Site With Redundancy On Router 881

Aug 13, 2012

is this possible to configure ipsec site to site vpn with redundancy using 2 cisco router 881?

View 2 Replies View Related

Copyrights 2005-15, All rights reserved