Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN client access remote dyanmic site-to-site VPN

I have a 3005 VPN concentrator with multiple dynamic site-to-site VPN connections. The remote sites are 501's. For management purposes I would like to be able to access the remote networks from a VPN client via the 3005. I have remote client VPN set up to the 3005 concentrator but I cannot access the dynamic remote sites.

In my remote 501's I have included my VPN network address in the "no nat" and "crypto" acls. from the remote locations I can access all subnets at my main location but cannot access any of the dynamic sites.

Is it possible? Here is a summary.

I want to use a Cisco VPN client to my main hub 3005. Once I am authenticated to the main network I would like to be able to access my remote dynamic site-to-site networks.

Thanks,

6 REPLIES
Silver

Re: VPN client access remote dyanmic site-to-site VPN

Make sure the VPN server (PIX Firewall, Cisco VPN Concentrator or a router) successfully assigns a DNS server IP address to the Cisco VPN Client. To check, issue the ipconfig/all command on your PC after you are connected with the VPN Client.

Gold

Re: VPN client access remote dyanmic site-to-site VPN

yes, it is possible.

you mentioned, "In my remote 501's I have included my VPN network address in the "no nat" and "crypto" acls.". however about the network list at the concentrator? have you add the remote vpn net?

New Member

Re: VPN client access remote dyanmic site-to-site VPN

In the concentrator I am using the Base Group. That is the only way I found to make a dynamic connection work. Because of using the base group I am actually creating a remote session and not a tunnel. Never-the-less I still do not have access from a VPN client to the dynamic network.

What about EZVPN? Will that work from a concentrator to a 501? Seems simple enough.

Gold

Re: VPN client access remote dyanmic site-to-site VPN

i hope this link may provide some help,

http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a0080094a86.shtml

further, regarding the design of the network, you mentioned the vpn is dynamic. it means that the remote site needs to initiate the vpn tunnel. so providing a user connects to the concentrator via vpn, this user will not be able to initiate the vpn between the remote site and the concentrator. it will only work providing the vpn between the remote site and the concentrator has already been established.

Gold

Re: VPN client access remote dyanmic site-to-site VPN

just wondering how you go.

New Member

Re: VPN client access remote dyanmic site-to-site VPN

Ended up using EZVPN to allow communication between VPN client and remote Dynamic sites. Works just fine now.

Thanks for your help!

119
Views
4
Helpful
6
Replies