IPsec VPN: multiple LANs on one side - is it possible?
I've an IPsec Site-to-Site VPN to a branch office (R2). There was one LAN (LAN1) at HQ and another (LAN2) at Branch office.
Tunnel termination points:
R1 - Microsoft ISA Server
R2 - Cisco 2921 ISR
LAN3 has been created recently, behind R2 (see the picture below):
So I need to gain an access to LAN3 from LAN1. How could I solve this problem? I see two options for now.
OPTION 1: Create a separate tunnel from R1 to R2
I see an issue here:
How could I define a separate key for this tunnel? If I execute something like this: crypto isakmp key LAN1_to_LAN2_key address 184.108.40.206 then LAN1 to LAN2 tunnel will be dropped because of the changed key
Everything else seems good - policy maps, route-maps, etc. Traffic could be distinguished between them
OPTION 2: Create a summary route in VPN config
R1 does not seem to support such kind of configuration (source, section "Quick policy mode negotiation fails with a "No policy configured" error")
It is interesting that from the ISA Server side you had to bring up another tunnel. I am glad that my suggestions helped you to solve it from the Cisco side. Thank you for using the rating system to mark this question as answered. This will help other readers in the forum to know that there is helpful information in this thread.
Thank you for posting back to the forum and updating us that you were able to just add another address range to the existing tunnel on the ISA Server. That makes sense and I agree that this is better than achieving the result by adding a new tunnel.
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...