<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need a help on Cisco IPSec Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635824#M1091123</link>
    <description>&lt;P&gt;I read all of it so, just adding the following configuration will be enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Router1(config)#&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;ip nat inside source list 100 interface fastethernet0/0 overload&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark -=[Define NAT Service]=-&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 deny ip 10.100.0.0 0.0.255.255 20.200.0.0 0.0.255.255&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 permit ip 10.100.0.0 0.0.255.255 any&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;Router2(config)#&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;ip nat inside source list 100 interface fastethernet0/0 overload&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark -=[Define NAT Service]=-&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 deny ip 20.200.0.0 0.0.255.255 10.100.0.0 0.0.255.255&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 permit ip 20.200.0.0 0.0.255.255 any&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 21 Jun 2022 13:03:19 GMT</pubDate>
    <dc:creator>kerimaksoy</dc:creator>
    <dc:date>2022-06-21T13:03:19Z</dc:date>
    <item>
      <title>Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635613#M1091105</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I am trying to do an exercise on the Cisco Packet Tracer which is:&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topo.png" style="width: 540px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154205iBCC25E5F3107962E/image-size/large?v=v2&amp;amp;px=999" role="button" title="topo.png" alt="topo.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and the config steps are:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="steps.png" style="width: 452px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154206i986B3FCF6DC8C23C/image-size/large?v=v2&amp;amp;px=999" role="button" title="steps.png" alt="steps.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am just new at Computer Networks and Cisco, so I wanted to ask if I did the all configurations correct or I need to change something on my config?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My Packet Tracer Topology:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="packet.png" style="width: 513px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154207i3A34BE1767250C0E/image-dimensions/513x250?v=v2" width="513" height="250" role="button" title="packet.png" alt="packet.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Router0 config:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;Router0(config)#int fa0/1&lt;BR /&gt;Router0(config-if)#ip add 10.100.0.1 255.255.0.0&lt;BR /&gt;Router0(config-if)#no shut&lt;BR /&gt;Router0(config)#int fa0/0&lt;BR /&gt;Router0(config-if)#ip add 30.100.0.1 255.255.0.0&lt;BR /&gt;Router0(config-if)#no shut&lt;BR /&gt;Router0(config)#ip route 0.0.0.0 0.0.0.0 30.100.0.2&lt;BR /&gt;Router0(config)#access-list 100 permit ip 10.100.0.0 0.0.255.255 20.200.0.0 0.0.255.255&lt;BR /&gt;Router0(config)#crypto isakmp policy 10
Router0(config-isakmp)#encryption aes 256
Router0(config-isakmp)#authentication pre-share
Router0(config-isakmp)#group 5
Router0(config)#crypto isakmp key secretkey address 30.100.0.2
Router0(config)#crypto ipsec transform-set R0-R1 esp-aes 256 esp-sha-hmac
Router0(config)#crypto map IPSEC-MAP 10 ipsec-isakmp 
Router0(config-crypto-map)#set peer 30.100.0.2
Router0(config-crypto-map)#set pfs group5
Router0(config-crypto-map)#set security-association lifetime seconds 86400
Router0(config-crypto-map)#set transform-set R0-R1 
Router0(config-crypto-map)#match address 100
Router0(config)#int fa0/0
Router0(config-if)#crypto map IPSEC-MAP
Router0(config)#access-list 120 permit tcp 10.100.0.0 0.0.255.255 host 20.200.0.10 eq 80&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;Router1 Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;Router1(config)#int fa0/0
Router1(config-if)#ip add 30.100.0.2 255.255.0.0
Router1(config-if)#no shut
Router1(config)#int fa0/1
Router1(config-if)#ip add 20.200.0.1 255.255.0.0
Router1(config-if)#no shut
Router1(config)#ip route 0.0.0.0 0.0.0.0 30.100.0.1
Router1(config)#access-list 100 permit ip 20.200.0.0 0.0.255.255 10.100.0.0 0.0.255.255
Router1(config)#crypto isakmp policy 10
Router1(config-isakmp)#encryption aes 256
Router1(config-isakmp)#authentication pre-share
Router1(config-isakmp)#group 5
Router1(config)#crypto isakmp key secretkey address 30.100.0.1
Router1(config)#crypto ipsec transform-set R1-R0 esp-aes 256 esp-sha-hmac
Router1(config)#crypto map IPSEC-MAP 10 ipsec-isakmp 
Router1(config-crypto-map)#set peer 30.100.0.1
Router1(config-crypto-map)#set pfs group5
Router1(config-crypto-map)#set security-association lifetime seconds 86400
Router1(config-crypto-map)#set transform-set R1-R0 
Router1(config-crypto-map)#match address 100
Router1(config)#int fa0/0
Router1(config-if)#crypto map IPSEC-MAP&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635613#M1091105</guid>
      <dc:creator>kerimaksoy</dc:creator>
      <dc:date>2022-06-21T10:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635628#M1091108</link>
      <description>&lt;PRE&gt;error in ACL of R0&lt;BR /&gt;Router0(config)#crypto isakmp policy 10
Router0(config-isakmp)#encryption aes 256
Router0(config-isakmp)#authentication pre-share
Router0(config-isakmp)#group 5
Router0(config)#crypto isakmp key secretkey address 30.100.0.2
Router0(config)#crypto ipsec transform-set R0-R1 esp-aes 256 esp-sha-hmac
Router0(config)#crypto map IPSEC-MAP 10 ipsec-isakmp 
Router0(config-crypto-map)#set peer 30.100.0.2
Router0(config-crypto-map)#set pfs group5
Router0(config-crypto-map)#set security-association lifetime seconds 86400
Router0(config-crypto-map)#set transform-set R0-R1 
Router0(config-crypto-map)#match address 100
Router0(config)#int fa0/0 &lt;BR /&gt;Router0(config-if)#&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;ip add 30.100.1&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;Router0(config-if)#crypto map IPSEC-MAP&lt;/PRE&gt;&lt;PRE&gt;Router0(config)#access-list 120 permit tcp &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;10&lt;/FONT&gt;&lt;/STRONG&gt;.100.0.0 0.0.255.255 host &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;20&lt;/STRONG&gt;&lt;/FONT&gt;.100.0.10 eq 80&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 09:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635628#M1091108</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-21T09:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635629#M1091109</link>
      <description>&lt;P&gt;high leve that should work - make sure on Router 0 the ACL should allow 10.x.xx network towards 20.x.x network&lt;/P&gt;
&lt;P&gt;below one.&lt;/P&gt;
&lt;PRE&gt;Router0(config)#access-list 120 permit tcp 30.100.0.0 0.0.255.255 host 10.100.0.10 eq 80&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we take this as no NAT involved, so routing in place, so should work as expected, if any issue post what is the issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also refer example config and understand each steps :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/867-cisco-router-site-to-site-ipsec-vpn.html" target="_blank"&gt;https://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/867-cisco-router-site-to-site-ipsec-vpn.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 09:36:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635629#M1091109</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-21T09:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635661#M1091111</link>
      <description>&lt;P&gt;I forget to write some of the commands of Router0 in the first time, So I edited them and change the last ACL as you said. Is that now fully correct configuration for my exercise?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But also now I figured that I don't have any interfaces or host with IP "20.100.0.10" which you wrote. Whydid you write that IP address?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635661#M1091111</guid>
      <dc:creator>kerimaksoy</dc:creator>
      <dc:date>2022-06-21T10:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635664#M1091112</link>
      <description>&lt;P&gt;Thanks for your reply, I edited my configuration. Is that now fully correct configuration for my exercise?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635664#M1091112</guid>
      <dc:creator>kerimaksoy</dc:creator>
      <dc:date>2022-06-21T10:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635668#M1091113</link>
      <description>&lt;P&gt;as per the task R2 and R3 ( not sure you have big network diagram) - so correct.&lt;/P&gt;
&lt;P&gt;task says allow branch to h1 allow any, and only internet http to H1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635668#M1091113</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-21T10:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635670#M1091114</link>
      <description>&lt;P&gt;sorry for ACL but for the tunnel to be UP you need to pass traffic between the two site,&amp;nbsp;&lt;BR /&gt;I correct the ACL 120 because it wrong and it can cause the traffic drop and not make tunnel UP&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635670#M1091114</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-21T10:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635688#M1091115</link>
      <description>&lt;P&gt;Thank you so much for your help, So I just wanted to ask is the edited configuration now fully correct?&lt;/P&gt;&lt;P&gt;I can't be sure because its my first time to configure that many thing together &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635688#M1091115</guid>
      <dc:creator>kerimaksoy</dc:creator>
      <dc:date>2022-06-21T10:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635697#M1091116</link>
      <description>&lt;PRE&gt;Router0(config)#access-list 120 permit tcp 10.100.0.0 0.0.255.255 host 20.200.0.10 eq 80&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;with that command aren't we allow only internet http to H1?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the allow any from branch to h1 I don't know the correct command so can you help me about it, please? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635697#M1091116</guid>
      <dc:creator>kerimaksoy</dc:creator>
      <dc:date>2022-06-21T10:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635771#M1091119</link>
      <description>&lt;P&gt;Can you share full edit config to make double check.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 11:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635771#M1091119</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-21T11:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635780#M1091120</link>
      <description>&lt;P&gt;i would suggest to read the document above posted and undertand the concept.(this is very important for learning part)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 11:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635780#M1091120</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-21T11:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635785#M1091121</link>
      <description>&lt;P&gt;Uhmm, I don't know how to share full edit config &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I edited my post with the last changes which you wrote to me, isn't that full edit?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 11:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635785#M1091121</guid>
      <dc:creator>kerimaksoy</dc:creator>
      <dc:date>2022-06-21T11:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635824#M1091123</link>
      <description>&lt;P&gt;I read all of it so, just adding the following configuration will be enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Router1(config)#&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;ip nat inside source list 100 interface fastethernet0/0 overload&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark -=[Define NAT Service]=-&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 deny ip 10.100.0.0 0.0.255.255 20.200.0.0 0.0.255.255&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 permit ip 10.100.0.0 0.0.255.255 any&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router1&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;Router2(config)#&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;ip nat inside source list 100 interface fastethernet0/0 overload&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark -=[Define NAT Service]=-&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 deny ip 20.200.0.0 0.0.255.255 10.100.0.0 0.0.255.255&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 permit ip 20.200.0.0 0.0.255.255 any&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Router2&lt;/SPAN&gt;(config)#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-list 100 remark&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Jun 2022 13:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635824#M1091123</guid>
      <dc:creator>kerimaksoy</dc:creator>
      <dc:date>2022-06-21T13:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help on Cisco IPSec Configuration</title>
      <link>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635868#M1091126</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1369336"&gt;@kerimaksoy&lt;/a&gt; your ACL 120 is incorrect, the request is to permit traffic from the internet (30.100.0.0/16) to H1, not from the branch site. Traffic from the branch would be routed over the VPN tunnel you've configured, so would not hit the outside interface unencrypted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You've also not configured the ACL on the outside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't use ACL 100 for NAT, as that number is already in use for the crypto ACL. Use another number specifically for NAT or use a named ACL.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 13:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-a-help-on-cisco-ipsec-configuration/m-p/4635868#M1091126</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-06-21T13:41:36Z</dc:date>
    </item>
  </channel>
</rss>

