Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPsec router to router + easy vpn clients

Hi,

I have a HQ with a Cisco 837. Some remote users are connecting via the easy vpn client. This works well. I now want to connect a branch office with a Cisco 827H via VPN whose ip-address is dynamically configured.

Can somebody give me a good setup for both routers. I find enough doc. for both setup's seperate but if i configure them both together something is messed up.

Thanks for a quick answer,

Kristine

4 REPLIES
New Member

Re: IPsec router to router + easy vpn clients

hi,

read this cisco page : http://www.cisco.com/warp/public/707/ios_804.html

regards,

New Member

Re: IPsec router to router + easy vpn clients

hi,

i already did but when i follow these instructions i came in conflict with the configuration for the easy vpn clients.

i configured the line like this :

crypto isakmp key cisco123 address 0.0.0.0 no-xauth

but these also makes that i cannot login anymore with the easy vpn client (because of the no-xauth of course - but that's what i want for the site-to-site vpn)

New Member

Re: IPsec router to router + easy vpn clients

hi,

remove easy vpn configuration ,

enable AAA.

and configure remote client authentication with:

-crypto map xx client authentication ...

-crypto map xx client authorization ...

have you ios version 12.2.13T ?

regards,

New Member

Re: IPsec router to router + easy vpn clients

i did it that way but how can i make a difference so that the site-to -site vpn has no authentication and the easy vpn clients does

i do have 12.2.13T

can you send me a config of both routers ?

i think because of this line at the HQ router :

crypto isakmp key cisco123 address 0.0.0.0 no-xauth

the fact you say 0.0.0.0 makes it also valid for the easy vpn clients - and not only for the site-to-site vpn

110
Views
0
Helpful
4
Replies
CreatePlease login to create content