<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: overcoming overlapping encryption domains in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/overcoming-overlapping-encryption-domains/m-p/622180#M1035762</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you can upload a drawing of this, i'll get you going.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Nov 2006 14:16:20 GMT</pubDate>
    <dc:creator>bhooker</dc:creator>
    <dc:date>2006-11-29T14:16:20Z</dc:date>
    <item>
      <title>overcoming overlapping encryption domains</title>
      <link>https://community.cisco.com/t5/network-security/overcoming-overlapping-encryption-domains/m-p/622179#M1035760</link>
      <description>&lt;P&gt;I have a site to site VPN being set up between 2 515s, each running 6.3(5).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have overlapping encryption domains (the servers we need to access at the remote location are in a network we already have locally defined).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I overcome this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Servers at the remote site are exposed to the internet for public access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the cookie cutter solution is to create static translations for all the servers we need to access (to public IPs) and then our match list ACL just references the public IPs (after translations).  Some of the servers at the remote site however are not internet facing and I would prefer to not have to A) use up public IPs with statics and B) not add translations to public IPs unless absolutely needed...(you know...defense in depth, another layer of security all that jazz...if someone adds a broad ACL by mistake it doesnt immediatly expose my internal servers if they dont have public translations in place).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I have any options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had this grand plan where I was hide-NATing traffic leaving my end and creating a network block static on the other end mapping the servers to a virtual non-routable network.  Then I would hit these non-routable IPs that I made up to access the servers.  Sadly I didnt look 2 steps ahead and realize this would preclude me from being able to add the public xlates required to expose these servers to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/overcoming-overlapping-encryption-domains/m-p/622179#M1035760</guid>
      <dc:creator>slug420</dc:creator>
      <dc:date>2019-03-11T09:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: overcoming overlapping encryption domains</title>
      <link>https://community.cisco.com/t5/network-security/overcoming-overlapping-encryption-domains/m-p/622180#M1035762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you can upload a drawing of this, i'll get you going.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2006 14:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/overcoming-overlapping-encryption-domains/m-p/622180#M1035762</guid>
      <dc:creator>bhooker</dc:creator>
      <dc:date>2006-11-29T14:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: overcoming overlapping encryption domains</title>
      <link>https://community.cisco.com/t5/network-security/overcoming-overlapping-encryption-domains/m-p/622181#M1035764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would this help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800949f1.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800949f1.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2006 15:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/overcoming-overlapping-encryption-domains/m-p/622181#M1035764</guid>
      <dc:creator>ggilbert</dc:creator>
      <dc:date>2006-11-29T15:52:59Z</dc:date>
    </item>
  </channel>
</rss>

