SA540: Need Sample Config to Setup VPN tunnel using DDNS

Unanswered Question
Jan 6th, 2010

Hi All,

I got a SA540 running DDNS, need some help / sample config on how to setup a VPN tunnel using Cisco VPN client.

Any guidelines would be very much appreciated.



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Steven Smith Wed, 01/06/2010 - 08:00

It works with the Quick VPN client, not the Cisco VPN client.  To make it work with the Quick VPN client is pretty simple.  Enable remote administration, then add IPSEC users as Cisco Quick VPN users.

erickimcisco Wed, 01/06/2010 - 16:50

Hello Steven,

Thanks for the prompt response. I tried to add an IPSec user as Cisco QVPN users, however it pop up with an error message saying "router need to change its ip address to 10.x.y.1 to avoid conflict... blah..".

My LAN is currently using subnet, I just want to create an IPSec tunnel back to my SA540. Is it a must to change to 10.x.y.1 network?

Or did I overlooked anything? Sorry, first time using Cisco product... still trying to get familiar with the setup.



Steven Smith Thu, 01/07/2010 - 08:04

Could you get a screen shot of the error?  Also, can you send me your config? 

Steven Smith Fri, 01/08/2010 - 14:11

Hi Eric,

I have heard back from development on this.

For quickvpn, having a local ip of isn't a good idea.  Many routers use as their default subnets.  When you have the local IP and the remote IP being the same, it doesn't work well.  So, we don't allow this because it is very likely to have this problem.  If you change the local IP address to something different, it should work.


This Discussion