Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Two office VPN set-up

I ahve a client that has two offices both with DSL. One office has a Cicsco 678 and the other a 675. The office with the 675 has an InstaGate EX2 appliance for firewall. They want to connect the offices and be able to do VPN with IPsec.

We can add another Instagate at the 678 end. My question is what is the best way to set this up? How many Real world IP addresses do we need? I assume we don't need to use NAT on the Cisco's? THe simplelest and least expensive set-up is what they are after. The customer had someone tell them the 67x's won't pass the IPSec toi the InstaGates. True or not?

Any help would be appreciated.

3 REPLIES
New Member

Re: Two office VPN set-up

As long as you don't use NAT and just route IP through the 678's it should work fine. You will need real IP addresses for all your hosts. If you go with a Cisco 800 series with the IPSec feature set, you can open a VPn tunnel from router to router and use NAT for your non-IPSec clients goin out to the Internet.

New Member

Re: Two office VPN set-up

Would 827's be the correct model? Any additional software need to be added or does the base software do the VPN tunnels? I assume I still only need one real IP address per router then.

I appreciate your help.

New Member

Re: Two office VPN set-up

We will install an 827 at each end with one IP address for each. We will use NAT on the 827's. They will need to do IPSec pass-through still. THe INstaGate EX2 firewalls at each location will be required still for e-mail and such so I will have them also be the firewall. Can this be accomplished still using NAT on the 827's?

Any example configs etc.?

Thanks in advance!

100
Views
0
Helpful
3
Replies
CreatePlease to create content