Cisco Systems ezvpn with network extension mode question

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
ezvpn with network extension mode question jj33 12-04-08
Posted by on December 4, 2008, 3:27 pm
Please log in for more thread options
I have a remote office connected to my main network using ezvpn in
network extension mode. The remote site is using a 2651XM router and
the server is a 3000 concentrator. The main goal of this solution was
that both networks be fully viable to each other. The currently used
DSL at the remote office will be replaced with private fiber in the
next year and I don't want to have to readdress either side.

I got it up and running for the most part. The problem now is that
the remote office can't access the public internet. I am not using
split tunneling because the docs I read said that split tunneling
didn't work with ezvpn in network extension mode. So, all my public
internet traffic is being sent back up to my vpn concentrator. Any
traffic that doesn't have a static route back into my internal network
(the private interface) doesn't work. The default route is via the
public interface.

So, I need some help. Here are some questions I could use answers or
pointers for:

1) can I do source routing so any traffic _from_ my remote office goes
into my internal network and, eventually, out through the normal
firewall egress point?

2) am I missing something obvious? A NAT translation or something?

3) Am I wrong about split tunneling? Can I use it with ezvpn?

4) should I abandon ezvpn and implement it the hard way, allowing me
to use split tunneling? If I do this can I implement the network
extension behaviour I want (where hosts on each side of the VPN can
directly address the other?

Thanks for any pointers.

--John

Similar ThreadsPosted
ezvpn with network extension mode question December 4, 2008, 3:27 pm
Cisco VPN 3002 Network Extension Mode August 11, 2005, 3:05 pm
ASA 5505 as hardware vpn client to PIX 501 or ASA 5505 with network extension mode activated June 16, 2007, 8:21 am
Fail to Convert Aironet 1242 from lightweight mode back to autonomous mode December 17, 2007, 12:21 am
Cisco 6500 - how to change from router mode to hybrid (switch mode) July 31, 2005, 9:50 pm
Can PIM-dense mode and PIM sparse Mode exchange routing related information December 13, 2007, 4:30 am
Lan Extension Backup Using xDSL October 16, 2006, 10:04 am
assinging an extension for incoming fxo line January 23, 2006, 9:30 am
Link Extension/DN - IPAddress(es) in Cisco CallManager Database May 26, 2006, 10:51 am
Re: Calls to an extension result in fast-busy when rolling to Unity Express voicemail October 28, 2008, 4:41 pm
ezvpn: ip pool necessary? June 27, 2006, 1:54 pm
Cisco 877 and EZVPN !?!?! July 6, 2007, 10:45 am
ezvpn with ipsec over tcp May 5, 2008, 12:06 am
EZVPN Problem on 877 to Cisco 300 Concentrator July 11, 2007, 4:27 am
Newbie: async mode dedicated versus async mode interactive!! June 8, 2006, 8:09 pm