Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

Network overlap?

I have 3015 concentrator at HQS and 3002 hardware client at site. We are using at concentrator private interfce and to hardware client private side.I am running network extension mode on hardware client. My tunnel comes up but i can not ping any thing at HQS private side which is 124.15.x.x/16. When i changed my address scheme at site to 123.x.x.x/16, i am able to ping HQS devices and browse HQS intranet. It works with any address but 124.15.x.x/16. Any idea why i am not able to browse or ping anything at HQS side if i use 124.15.x.x/16 or 24 or etc subnet at site. Thanks


Re: Network overlap?

When you use and on netblocks on ends of the same vpn tunnel, you are using the same ip netspace in both locations - 124.15.x.x/16. Nothing will travel through the tunnel because all machines will think that all hosts numbered 124.15.x.x/16 are on the local subnet/network, and thus never hit the vpn device.

Community Member

Re: Network overlap?

I even used different netmask at hardware client private interface side but it still did not work. I used /24 at hardware client. Thanks


Re: Network overlap?

Yes, but that doesn't matter. If you did not change anything on the HQ side, then all hosts there would continue to think that all hosts in the netblock are directly reachable, and thus those packets will not be sent to the default gateway: is the default gateway. it has a route to the vpn device making the point to point ipsec tunnel. is a server at HQ.

even if you use at the remote site, server will think all hosts in that block are directly accessible as a result of *its* subnet mask being /16 (, and thus will not send packets for them ( the default gateway.

CreatePlease to create content