<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Overlapping subnet mask in VPN configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/overlapping-subnet-mask-in-vpn-configuration/m-p/690514#M1062890</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Siddhartha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have not missed anything. This is expected behavior with overlapping subnet and this configuration is not supported in VPN for the very same reason that you are experiencing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best workaround would be, to have one of the remote site NAT their source IP when tunneling traffic to your network. So, you can build the L2L Tunnel based upon the NATed IP Address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Similar Configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800949f1.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800949f1.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Please rate all helpful posts **&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Nov 2006 19:22:54 GMT</pubDate>
    <dc:creator>ajagadee</dc:creator>
    <dc:date>2006-11-02T19:22:54Z</dc:date>
    <item>
      <title>Overlapping subnet mask in VPN configuration</title>
      <link>https://community.cisco.com/t5/network-security/overlapping-subnet-mask-in-vpn-configuration/m-p/690513#M1062870</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one VPN configured over Pix 506-e 6.3(4) for a site with remolte local network is 192.168.128.0 255.255.255.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have told to configure new VPN for another site for that the remote LAN is 192.168.128.0 255.255.252.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I configured this VPN no traffic was generated and no VPN tunnel created for New Site(192.168.128.0/22) .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found that a tunnel created for Old site(192.168.128.0/24) and all packets are going on this route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this due to overlapping of remote LAN or I have missed some ACL configuration.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks in Advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Siddhartha &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:16:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/overlapping-subnet-mask-in-vpn-configuration/m-p/690513#M1062870</guid>
      <dc:creator>sid916207</dc:creator>
      <dc:date>2020-02-21T09:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnet mask in VPN configuration</title>
      <link>https://community.cisco.com/t5/network-security/overlapping-subnet-mask-in-vpn-configuration/m-p/690514#M1062890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Siddhartha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have not missed anything. This is expected behavior with overlapping subnet and this configuration is not supported in VPN for the very same reason that you are experiencing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best workaround would be, to have one of the remote site NAT their source IP when tunneling traffic to your network. So, you can build the L2L Tunnel based upon the NATed IP Address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Similar Configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800949f1.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800949f1.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Please rate all helpful posts **&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2006 19:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/overlapping-subnet-mask-in-vpn-configuration/m-p/690514#M1062890</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2006-11-02T19:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnet mask in VPN configuration</title>
      <link>https://community.cisco.com/t5/network-security/overlapping-subnet-mask-in-vpn-configuration/m-p/690515#M1062903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Siddhartha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2006 10:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/overlapping-subnet-mask-in-vpn-configuration/m-p/690515#M1062903</guid>
      <dc:creator>sid916207</dc:creator>
      <dc:date>2006-11-07T10:07:26Z</dc:date>
    </item>
  </channel>
</rss>

