cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
529
Views
0
Helpful
4
Replies

NAT and VPN on 1711

I have a cisco 1711 at the edge. I have two different customer networks that I would like to connect to via vpn at the same time to manage there server via our hp openview manager. They also have a cisco 1711 at the edge. The problem is they both have the same ip scheme 10.1.1.x. Any suggestions???

4 Replies 4

atdhingr
Level 1
Level 1

Do you need to be able to initiate the tunnel from sides, if not use PAtted IP at the customer's end for vpn and then initiate the tunnel from your end.

Let me know your comments

Atul.

I need to have the tunnel initiated from the customers end as I have a static IP and they may have a dynamic ip.

192.168.1.xRouterMain(200.200.200.200)-----------100.100.100.100RouterCustomer(10.1.1.x)

NAT list on RouterMain:

deny ip 192.168.1.x to 100.100.100.100

permit ip 192.168.1.x to any

Crypto list on RouterMain:

permit ip 192.168.1.x to 100.100.100.100

_____________________________

NAT list on RouterCustomer:

permit ip 10.1.1.x. to any

Crypto list on RouterCustomer:

permit ip 100.100.100.100 to 192.168.1.x

In the above way you can initiate it from behind the RouterCustomer because it uses PATed ip you can have same internal network behind another router (RouterCustomer2) and then use its PAT IP for crypto.

let me know your comments

that should do the trick....thanks,

Ken

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: