Cisco Systems Allow Cisco vpn client pool down a site to site VPN

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Allow Cisco vpn client pool down a site to site VPN tweety 07-29-08
Posted by tweety on July 29, 2008, 3:28 pm
Please log in for more thread options
Hi there,

I was wondering if the following is possible?


I am terminating a vpn client ( pool 10.10.10.0 /24 ) onto router A
and allowing access to 192.168.100.0 /24 , this is router A's local
lan. Router A also has a site to site VPN to router B. This is from
net 192.168.100.0 /24 to 192.168.200.0 /24 This is as follows.....


Remote Client 10.10.10.0 /24
|
|
192.168.100.0 /24
|
|
|
Router A
|
|
|
Router B
|
|
|
192.168.200.0 /24


Is there anyway that the remote client would be able to go down the
Site to site VPN and see Router B's lan?


I am looking fo the remote clients to be able to access resources on
Router B's lan.


Thanks for any help or pointers anyone can provide.


Andrew

Posted by Artie Lange on July 29, 2008, 3:41 pm
Please log in for more thread options
tweety wrote:
> Hi there,
>
> I was wondering if the following is possible?
>
>
> I am terminating a vpn client ( pool 10.10.10.0 /24 ) onto router A
> and allowing access to 192.168.100.0 /24 , this is router A's local
> lan. Router A also has a site to site VPN to router B. This is from
> net 192.168.100.0 /24 to 192.168.200.0 /24 This is as follows.....
>
>
> Remote Client 10.10.10.0 /24
> |
> |
> 192.168.100.0 /24
> |
> |
> |
> Router A
> |
> |
> |
> Router B
> |
> |
> |
> 192.168.200.0 /24
>
>
> Is there anyway that the remote client would be able to go down the
> Site to site VPN and see Router B's lan?
>
>
> I am looking fo the remote clients to be able to access resources on
> Router B's lan.
>
>
> Thanks for any help or pointers anyone can provide.
>
>
> Andrew

From router A:

ip route 192.168.200.0/24 <IP of RouterB> ?

Posted by Artie Lange on July 29, 2008, 3:48 pm
Please log in for more thread options
Artie Lange wrote:

>
> From router A:
>
> ip route 192.168.200.0/24 <IP of RouterB> ?


Should be

ip route 192.168.200.0/24 <IP router A that knows how to get to B>

In that scenario, the VPN client would forward the packet to the router
A that in turn would have a route to router B....

Posted by tweety on July 29, 2008, 4:03 pm
Please log in for more thread options
> Artie Lange wrote:
>
> > =A0From router A:
>
> > ip route 192.168.200.0/24 <IP of RouterB> ?
>
> Should be
>
> ip route 192.168.200.0/24 <IP router A that knows how to get to B>
>
> In that scenario, the VPN client would forward the packet to the router
> A that in turn would have a route to router B....

Hi guys i appreciate the quick answers :)

However i would then need to make sure the client pool would not nat
going from router A to router B?

Posted by News Reader on July 29, 2008, 4:17 pm
Please log in for more thread options
tweety wrote:
>> Artie Lange wrote:
>>
>>> From router A:
>>> ip route 192.168.200.0/24 <IP of RouterB> ?
>> Should be
>>
>> ip route 192.168.200.0/24 <IP router A that knows how to get to B>
>>
>> In that scenario, the VPN client would forward the packet to the router
>> A that in turn would have a route to router B....
>
> Hi guys i appreciate the quick answers :)
>
> However i would then need to make sure the client pool would not nat
> going from router A to router B?

It sounds like the RAVPN and site-to-site VPN are terminated on the same
interface of Router A.

Since traffic between the RAVPN Client and Router B's internal network
is not transiting from an "ip nat inside" to an " ip nat outside"
interface on Router A, I don't see NAT as a concern on Router A.

However, traffic returning from Router B's internal network to the RAVPN
Client would need to be exempted from NAT on Router B.

This traffic would also have to be included in the crypto ACLs of both
routers.

Best Regards,
News Reader

Similar ThreadsPosted
Allow Cisco vpn client pool down a site to site VPN July 29, 2008, 3:28 pm
Vpn site to site + vpn cisco client access list problem. August 7, 2006, 10:35 am
PIX 7.x VPN Client and site to site VPN's June 9, 2006, 12:25 pm
combining site to site vpn & vpn client on 837 April 2, 2007, 2:20 pm
Site to Site VPN routing - Cisco 1841 to Nortel VPN Router 1010 September 21, 2007, 1:46 pm
I want to create Site to Site VPN with Cisco PIX501 and Linksys RV082 September 10, 2007, 3:46 am
Site to Site VPN error on Cisco ASA5500 and router 1800 January 4, 2008, 1:55 pm
VPN site-to-site betweem Cisco 1841 and SonicWall 170 January 2, 2006, 10:04 am
VPN Client & site-to-site, IOS 12.3 August 10, 2005, 9:56 pm
Pix site to site and client VPN August 4, 2006, 2:26 pm
PIX VPN site to site and client December 5, 2006, 2:06 pm
VPN Site To Site between a Cisco 831 and a bintec X1200 October 27, 2005, 1:45 pm
VPN Site To Site between a Cisco 831 and a bintec X1200 October 27, 2005, 1:45 pm
VPN Site To Site between a Cisco 831 and a bintec X1200 October 27, 2005, 1:45 pm
Site to Site VPN Issues w/ Cisco Router/NAT - I'm 90% of the way there. :) June 23, 2006, 1:43 pm