cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
859
Views
10
Helpful
4
Replies

VPN Design - router with only 1 network interface

rts-net-support
Level 1
Level 1

Hello all,

This may sound like a dumb question. We need to set up a new VPN connection to a customer and they have an IPSEC capable router with only 1 network interface. It has a private IP, the router is placed in a DMZ.

Is it possible to terminate a VPN connection on that router ? Or you need 2 network interfaces (one private, one public) ?

Thanks in advance,

Stefan

4 Replies 4

abdel_n
Level 1
Level 1

Hi,

You know what i have just tried to assign a crypto map to a subinteface with dotq encapsulation and the router accepted it and enabled ISAKMP on it!

So with another subinterface with another dotq vlan encapsulation i guess you can terminate a vpn connection to the first one and forward decrypted traffic to the second.

I will try this later and i will post results as soon as i've done it (if it work of caurse)

Interesting. Please, post results with some configuration examples, when you have them ;)

Thanks,

Stefan

Hi Stefan,

Here is the configuration with some explanations.

I hope this will help you.

That's an excellent explanation, thanks a lot.