<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing troubles behind VPN3000 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-troubles-behind-vpn3000/m-p/282933#M1059844</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use vpn3000 with one connection group and an ACS server for users authentication (with RADIUS). There are two groups configured in ACS with different IP pools (10.20.1.x and 10.20.2.x). Private interface of the VPN3000 is configured with 10.7.2.1 and is connected to a 3550.&lt;/P&gt;&lt;P&gt;If a VPN client connects to the concentrator that  gets him a 10.20.x.y IP, he can't ping the switch.&lt;/P&gt;&lt;P&gt;If I configured a 'test user' to get a 10.7.2.x IP, I can ping all the network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured the 3550 port with:&lt;/P&gt;&lt;P&gt;    interface FastEthernet0/5&lt;/P&gt;&lt;P&gt;       switchport mode access&lt;/P&gt;&lt;P&gt;       switchport access vlan 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    interface vlan 8&lt;/P&gt;&lt;P&gt;       ip address 10.7.2.254 255.255.255.0&lt;/P&gt;&lt;P&gt;       ip address 10.20.1.254 255.255.255.0 secondary&lt;/P&gt;&lt;P&gt;       ip address 10.20.2.254 255.255.255.0 secondary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and in vpn3000 for default gateway 10.7.2.254 and tunnel gateway 10.7.2.254..&lt;/P&gt;&lt;P&gt;I want then to have a vlan for each IP pools configured in ACS...&lt;/P&gt;&lt;P&gt;Any one could help me to resolve this trouble ?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:31:54 GMT</pubDate>
    <dc:creator>gauthraj</dc:creator>
    <dc:date>2020-02-21T07:31:54Z</dc:date>
    <item>
      <title>Routing troubles behind VPN3000</title>
      <link>https://community.cisco.com/t5/network-security/routing-troubles-behind-vpn3000/m-p/282933#M1059844</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use vpn3000 with one connection group and an ACS server for users authentication (with RADIUS). There are two groups configured in ACS with different IP pools (10.20.1.x and 10.20.2.x). Private interface of the VPN3000 is configured with 10.7.2.1 and is connected to a 3550.&lt;/P&gt;&lt;P&gt;If a VPN client connects to the concentrator that  gets him a 10.20.x.y IP, he can't ping the switch.&lt;/P&gt;&lt;P&gt;If I configured a 'test user' to get a 10.7.2.x IP, I can ping all the network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured the 3550 port with:&lt;/P&gt;&lt;P&gt;    interface FastEthernet0/5&lt;/P&gt;&lt;P&gt;       switchport mode access&lt;/P&gt;&lt;P&gt;       switchport access vlan 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    interface vlan 8&lt;/P&gt;&lt;P&gt;       ip address 10.7.2.254 255.255.255.0&lt;/P&gt;&lt;P&gt;       ip address 10.20.1.254 255.255.255.0 secondary&lt;/P&gt;&lt;P&gt;       ip address 10.20.2.254 255.255.255.0 secondary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and in vpn3000 for default gateway 10.7.2.254 and tunnel gateway 10.7.2.254..&lt;/P&gt;&lt;P&gt;I want then to have a vlan for each IP pools configured in ACS...&lt;/P&gt;&lt;P&gt;Any one could help me to resolve this trouble ?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-troubles-behind-vpn3000/m-p/282933#M1059844</guid>
      <dc:creator>gauthraj</dc:creator>
      <dc:date>2020-02-21T07:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Routing troubles behind VPN3000</title>
      <link>https://community.cisco.com/t5/network-security/routing-troubles-behind-vpn3000/m-p/282934#M1059845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A similar configuration example using RADIUS for user authentication is available at &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a00800a3b88.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a00800a3b88.shtml&lt;/A&gt;. Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Aug 2004 12:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-troubles-behind-vpn3000/m-p/282934#M1059845</guid>
      <dc:creator>drolemc</dc:creator>
      <dc:date>2004-08-02T12:59:09Z</dc:date>
    </item>
  </channel>
</rss>

