Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > SiteA to SiteB IPsec VPN and SiteA to SiteC, but SiteB and SiteC havethe same IP Range

Reply
Thread Tools

SiteA to SiteB IPsec VPN and SiteA to SiteC, but SiteB and SiteC havethe same IP Range

 
 
googlegroups@ruetsche.com
Guest
Posts: n/a
 
      11-17-2007

Hi Group

I try to build a 2nd IPSec Tunnel from SiteA to SiteC, but SiteC have
the same IP Address Range like SiteB:

SiteA: 192.168.2.0/24 / PIX OS 8.0(2)
SiteB: 192.168.33.0/24 / PIX OS 6.3(5)
SiteC: 192.168.33.0/24 / PIX OS 6.3(5)

The tunnel from A to B is up and runs fine.

I want to translate to Adresses for the SiteC on the PIX on SiteA
(192.168.233.0 [SiteA] > 192.168.33.0 [for SiteC]) and i saw this
example:

http://www.cisco.com/en/US/partner/p...808c9950.shtml

I play arround with this example, but i don't want to translate on the
PixA (SiteA) the 192.168.1.0 to 172.18.1.0, i want to translate on the
PixA the Address 10.1.0.0 to 172.18.1.0 for example. Sometimes i loos
the connection to SiteB, but i never bring up the tunnel to SiteC.

Is there anyone who can give me a tip how i need to build the access-
list and static statement?

Thank you lot.

ivo

 
Reply With Quote
 
 
 
 
Brian V
Guest
Posts: n/a
 
      11-17-2007

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> Hi Group
>
> I try to build a 2nd IPSec Tunnel from SiteA to SiteC, but SiteC have
> the same IP Address Range like SiteB:
>
> SiteA: 192.168.2.0/24 / PIX OS 8.0(2)
> SiteB: 192.168.33.0/24 / PIX OS 6.3(5)
> SiteC: 192.168.33.0/24 / PIX OS 6.3(5)
>
> The tunnel from A to B is up and runs fine.
>
> I want to translate to Adresses for the SiteC on the PIX on SiteA
> (192.168.233.0 [SiteA] > 192.168.33.0 [for SiteC]) and i saw this
> example:
>
> http://www.cisco.com/en/US/partner/p...808c9950.shtml
>
> I play arround with this example, but i don't want to translate on the
> PixA (SiteA) the 192.168.1.0 to 172.18.1.0, i want to translate on the
> PixA the Address 10.1.0.0 to 172.18.1.0 for example. Sometimes i loos
> the connection to SiteB, but i never bring up the tunnel to SiteC.
>
> Is there anyone who can give me a tip how i need to build the access-
> list and static statement?
>
> Thank you lot.
>
> ivo
>


You need to do the NAT on site C's Pix not site A's.

 
Reply With Quote
 
 
 
 
googlegroups@ruetsche.com
Guest
Posts: n/a
 
      11-18-2007

Thank you Brian

When i define the NAT on SiteC, it works. Is there no chance to do
that on SiteA?




On 17 Nov., 12:53, "Brian V" <(E-Mail Removed)> wrote:
> <(E-Mail Removed)> wrote in message
>
> news:(E-Mail Removed)...
>
>
>
>
>
> > Hi Group

>
> > I try to build a 2ndIPSecTunnel fromSiteAtoSiteC, butSiteChave
> > the same IP Address Range likeSiteB:

>
> >SiteA: 192.168.2.0/24 / PIX OS 8.0(2)
> >SiteB: 192.168.33.0/24 / PIX OS 6.3(5)
> >SiteC: 192.168.33.0/24 / PIX OS 6.3(5)

>
> > The tunnel from A to B is up and runs fine.

>
> > I want to translate to Adresses for theSiteCon the PIX onSiteA
> > (192.168.233.0 [SiteA] > 192.168.33.0 [forSiteC]) and i saw this
> > example:

>
> >http://www.cisco.com/en/US/partner/p...ps2030/product...

>
> > I play arround with this example, but i don't want to translate on the
> > PixA (SiteA) the 192.168.1.0 to 172.18.1.0, i want to translate on the
> > PixA the Address 10.1.0.0 to 172.18.1.0 for example. Sometimes i loos
> > the connection toSiteB, but i never bring up the tunnel toSiteC.

>
> > Is there anyone who can give me a tip how i need to build the access-
> > list and static statement?

>
> > Thank you lot.

>
> > ivo

>
> You need to do the NAT on site C's Pix not site A's.


 
Reply With Quote
 
Brian V
Guest
Posts: n/a
 
      11-18-2007

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> Thank you Brian
>
> When i define the NAT on SiteC, it works. Is there no chance to do
> that on SiteA?
>
>
>
>
> On 17 Nov., 12:53, "Brian V" <(E-Mail Removed)> wrote:
>> <(E-Mail Removed)> wrote in message
>>
>> news:(E-Mail Removed)...
>>
>>
>>
>>
>>
>> > Hi Group

>>
>> > I try to build a 2ndIPSecTunnel fromSiteAtoSiteC, butSiteChave
>> > the same IP Address Range likeSiteB:

>>
>> >SiteA: 192.168.2.0/24 / PIX OS 8.0(2)
>> >SiteB: 192.168.33.0/24 / PIX OS 6.3(5)
>> >SiteC: 192.168.33.0/24 / PIX OS 6.3(5)

>>
>> > The tunnel from A to B is up and runs fine.

>>
>> > I want to translate to Adresses for theSiteCon the PIX onSiteA
>> > (192.168.233.0 [SiteA] > 192.168.33.0 [forSiteC]) and i saw this
>> > example:

>>
>> >http://www.cisco.com/en/US/partner/p...ps2030/product...

>>
>> > I play arround with this example, but i don't want to translate on the
>> > PixA (SiteA) the 192.168.1.0 to 172.18.1.0, i want to translate on the
>> > PixA the Address 10.1.0.0 to 172.18.1.0 for example. Sometimes i loos
>> > the connection toSiteB, but i never bring up the tunnel toSiteC.

>>
>> > Is there anyone who can give me a tip how i need to build the access-
>> > list and static statement?

>>
>> > Thank you lot.

>>
>> > ivo

>>
>> You need to do the NAT on site C's Pix not site A's.

>


Not without getting very ugly in the config. I.E. addding an additional
outside interface to Pix A, moving NAT to the internet router, subnet
specific routing, etc.... The problem is that Site A has no way to
differentiate what site gets NAT'd, you have a single "nat (inside,outside)"
which covers both destination subnets.

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN site to site & Remote access VPN ( vpn client) over the same interface pasatealinux Cisco 1 12-17-2007 07:41 PM
PIX ipsec client vpn, how to create access-lists for multiple vpn groups Mephesto Cisco 2 06-09-2005 05:23 PM
IPSec VPN problem with a CISCO C827 ADSL Router and a Nortel Contivity VPN Client mw Cisco 2 04-20-2005 08:18 PM
PIX 501: Access an IPSEC VPN through a PPTP VPN - is this possible? Alex Cisco 3 05-11-2004 11:26 PM
VPN IPSEC connection between a cisco 17xx and Nortel vpn box Joris Deschacht Cisco 0 10-16-2003 02:13 PM



Advertisments