Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

help needed - tunnel from behind ADSL router

I have a situation in which I require to set-up IPSec tunnel in between two 1841 routers. This is normally two minutes job, in this case however one of the routers sits on a private LAN behind ADSL router (at the moment there is no reasonable way to get around it).


1841-1 <-> WAN <-> ADSL Router <-> 1841-2


FE0/1 Private LAN

FE0/0 Public IP




ADSL Router

Public IP


Private LAN1




FE0/1 LAN2 IP require to communicate over the IPSec tunnel.

Could you please advice me on 1) what is the most practical way to set this up with out loosing sanity; and 2) Could you maybe point me to some documentation that deals with this specific scenario?



Re: help needed - tunnel from behind ADSL router

Does '1841-2' have a corresponding public IP?

If so, there should be no issue establishing an IPSEC VPN using the public IP address.

If there is not a public IP for '1841-2' I cannot see any way that you'd be able to get this to work.

New Member

Re: help needed - tunnel from behind ADSL router

'1841-2' does not have public IP (it "fakes" to have one).

IPsec tunnel is fully working now.

In the process though I have learned that it depends on what ADSL modem you are using to get this working.

Check out for example (this is the one I got working).

You can thus give your Cisco router a private IP behind ADSL router and then follow the steps from the knowledge base article above on ADSL modem (if you have same type available).

In addition then, on your Cisco router - you require to add loopback 0 interface and give it public IP of your ADSL router (yes - your adsl router WAN interface and loopback interface on your Cisco router have now the same public IP).

As the last step, on your Cisco router, change tunnel interface: source interface loopback 0 and destination your remote gateway.

I am going to try different modems, many models can actually do this, but the documentation is often unimpressive.

It is possible that there are better ways to do this, if so, please let me know.

If you wish to have more details about the set-up, let me know.