×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

only one remote network statement in site-to-site vpn?

Answered Question
Aug 5th, 2013
User Badges:

Hi,


I'm wondering about in case of site-to-site vpn, we can only define one network statement for peer branch office network?


if there are one more local network in peer site, then, how to define those for peer local subnet?


Can anyone response about my question?


Thanks.

Correct Answer by Marius Gunnerud about 4 years 2 weeks ago

If I understand your question correctly you are wondering how to add another subnet to an existing site to site VPN tunnel?


If that is correct you can add that network to the crypto ACL of the existing site to site tunnel.  But you must tear down and rebuild the tunnel for it to take effect.


once you have added the required configuration issue the following commands to tear down the tunnel.  Keep in mind that doing this will disconnect any users on the VPN so it is best to let the users know when you are going to do this so they are not connected at that time.


clear crypto isakmp


clear crypto ipsec sa

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Marius Gunnerud Tue, 08/06/2013 - 02:02
User Badges:
  • Red, 2250 points or more
  • Cisco Designated VIP,

    2017 Firewalling

If I understand your question correctly you are wondering how to add another subnet to an existing site to site VPN tunnel?


If that is correct you can add that network to the crypto ACL of the existing site to site tunnel.  But you must tear down and rebuild the tunnel for it to take effect.


once you have added the required configuration issue the following commands to tear down the tunnel.  Keep in mind that doing this will disconnect any users on the VPN so it is best to let the users know when you are going to do this so they are not connected at that time.


clear crypto isakmp


clear crypto ipsec sa

syjeon Tue, 08/06/2013 - 16:24
User Badges:

I recalled cisco ios vpn for site-to-site vpn were able to add one more remote subnet. by the way, some of Nokia site-to-site vpn box can't. that is possible to enable only one remote subnet. for instance, if we mentioned 10.x.x.x/8, then it can't be such as one more 20.0.0.0/8 like so.


Thanks.

Marius Gunnerud Wed, 08/07/2013 - 00:57
User Badges:
  • Red, 2250 points or more
  • Cisco Designated VIP,

    2017 Firewalling

I am not familiar with Nokia VPNs, but as I mentioned this is possible on Cisco.  It just requires the tunnel to be re-established for the changes to take effect.

Actions

This Discussion