I have two sites connecting via a Hub site Bangalore, where I have a Pix 506E. I have got site-site VPN tunnel on both inside and outside iterface of the Pix. Can i get the two communicate amongst themselves? Will 2 IPSEC tunnels on 2 different interfaces on the same PIX work and communicate between the two sites?
Hi .. yes you can but you will have to include the spokes sites on the respective crypto map you are using .for example if the hub site is 10.10.10.0/24, spoke 1 is 126.96.36.199/24 and spoke 3 is 188.8.131.52/24 then
1.- tunnel from spoke one to Hub needs to include
from 184.108.40.206/24 to 10.10.10.0/24
from 220.127.116.11/24 to 18.104.22.168/24
2.- tunnel from spoke two to Hub needs to include
from 22.214.171.124/24 10.10.10.0/24
from 126.96.36.199/24 188.8.131.52/24
The access-list applied to the crypto map on your hub router has to be modified accordingly as well.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...