Cisco Systems Remote VPN router behind internet access router

please rate
this thread
Posted by Markus Marquardt on June 14, 2007, 8:34 am
Please log in for more thread options
Hello,

maybe someone could give me a hint about this scenario:

<local LAN>
|
|
<PIX515e/7.2>
|Public IP
|
|
<Internet>
|
|
|Public IP
<Internet gw>
|Private IP
|
|Private IP
<VPN gateway>
|Private IP
|
<remote LAN>

I want to establish a VPN connection between our local PIX and the
remote VPN gateway. The remote gateway is not directly connected to the
internet. It's connected to <Internet gw> which forwards all packets and
is doing 1:1 NAT between the public IP address and the private IP address.

When trying to establish the VPN tunnel, on the PIX i get something like

Group = <something>, IP = <Public IP internet GW>, Rejecting IPSec
tunnel: no matching crypto map entry for remote proxy <Private IP VPN
gateway>/255.255.255.255/0/0 local proxy <Public IP
PIX>/255.255.255.255/0/0 on interface outside

The reason are the different public/private addresses which are seen for
the remote VPN gateway. Is there any way to get around this? NAT-T?
Which address should be used for the crypto map: The public or private
address of the remote VPN gw?

With kind regards
Markus

Posted by Newbie72 on June 14, 2007, 9:57 am
Please log in for more thread options

The first question is What type of hardware are you using? 2nd
question is what type of hardware are you connecting to?

Check out the below link it should be able to answer most of your
questions if you r using PIX 6.3
http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/sit2site.html

here is a link if you are using Pix 7.x or ASA appliance
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a87f7.shtml



Posted by Markus Marquardt on June 14, 2007, 10:40 am
Please log in for more thread options
Newbie72 wrote:

See above...


Remote internet gw: I don't know
Remote VPN gw: Checkpoint-Something

The problem is not to create an vpn connection at all, the problem is
that the remote vpn gw is connected via a rfc1918 transfer network to
the internet.

Regards
Markus

This Thread Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Remote VPN router behind internet access router Markus Marquardt 06-14-07
Related PostsForumDate
Internet access for vpn clients Cisco Systems 2007-02-26
PIX Internet access OK - but cannot get to VPN Cisco Systems 2006-08-31
Internet access at convention centers -> how to hack / crack... Wireless Networking 2009-05-01
VPN causes Internet to stop Wireless Networking 2007-12-08
using 2nd router as access point for connecting PS2 Wireless Networking 2006-11-26
WRT54G No Internet Access Wireless Networking 2007-11-22
Router--Router--Internet setup not working.... Wireless Networking 2007-09-17
Can't access router without changing adapter settings Wireless Networking 2006-02-12
Sharing internet access with other laptops (Verizon card... Wireless Networking 2007-07-15
How to allow only internet access to wireless clients? Wireless Networking 2007-04-23
VPN and Internet Access Virtual Private Networks 2006-04-01
VPN and Internet Access Virtual Private Networks 2006-04-01
Turning NetGear from router to access point only? Wireless Networking 2005-09-28
BYO Wireless Internet Access Provider Wireless Networking 2006-09-19
Latest PostsForumRSS
Can an intruder remotely reset a Linksys WRT54G v5 router to... Wireless Networking
Bob L. ( Message forwarded) CCTV, Alarms and other Physical Security
Mac to VLAN mapping on Cisco switches Cisco Systems
Sality virus help how to get rid of w32 Sality.a e malware... Networking Firewalls
Re: Bill Pay down [telecom] General Telecommunications Forum
Question about SmartHome 1132CU programming General Home Automation
Toronto Free Cisco Seminar CCNA CCNP CCIE & BBQ Cisco Certification
SIP Proxy Server on Windows Vista?‏ Voice-Over-IP
WE ARE BUYING NETWORKING - TELECOM USED AND NEW EQUIPMENT CI... Ethernet LAN
Satellite or cable service for local TV broadcasts? Cable Modems
Modular UPS Telecom Technical
Verizon's DSL or not in my upcoming home area? Digital Subscriber Line
Water Damage & Fire Damage Sterling Heights Michigan Nortel Networks
About the Cat 7 cable LAN and Telecom Cabling
Fire Damage Clean Up & Smoke Damage Restoration Home Automation
VPN Soft Reset? Virtual Private Networks
FA: Joe Kane's VIDEO ESSENTIALS laserdisc Home Theater
Fiber Optics in Access Network_CFP Fiber Optics
Which Forum is best for professionals in the alarm business Electronic Security in UK
SIP SDK 3.6 Video Conferencing
Residential Cabling Guide Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Order Now for Instant Download