<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSEC setup where LAN not directly connected in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629417#M196134</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have designing a IPSEC VPN connect but it looks not like general example.&amp;nbsp;&amp;nbsp; Following environment setup description with network diagram for reference.&amp;nbsp; Could you please advise?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Environment Setup&lt;/P&gt;&lt;P&gt;- Form IPSEC VPN between two site via ASA, which ASA is routable facing to Internet&lt;BR /&gt;- SERVER default gateway is Internal L3 Switch&lt;BR /&gt;- L3 Switch default gateway is ASA&lt;BR /&gt;- NO NAT require between ASA to SERVER&lt;/P&gt;&lt;P&gt;Question: How to config IPSEC site-to-site VPN to establish connection between LAN A &amp;amp; LAN B? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:38:11 GMT</pubDate>
    <dc:creator>Machi Ma</dc:creator>
    <dc:date>2019-03-12T05:38:11Z</dc:date>
    <item>
      <title>IPSEC setup where LAN not directly connected</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629417#M196134</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have designing a IPSEC VPN connect but it looks not like general example.&amp;nbsp;&amp;nbsp; Following environment setup description with network diagram for reference.&amp;nbsp; Could you please advise?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Environment Setup&lt;/P&gt;&lt;P&gt;- Form IPSEC VPN between two site via ASA, which ASA is routable facing to Internet&lt;BR /&gt;- SERVER default gateway is Internal L3 Switch&lt;BR /&gt;- L3 Switch default gateway is ASA&lt;BR /&gt;- NO NAT require between ASA to SERVER&lt;/P&gt;&lt;P&gt;Question: How to config IPSEC site-to-site VPN to establish connection between LAN A &amp;amp; LAN B? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629417#M196134</guid>
      <dc:creator>Machi Ma</dc:creator>
      <dc:date>2019-03-12T05:38:11Z</dc:date>
    </item>
    <item>
      <title> I think below is a good</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629418#M196135</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think below is a good guide&lt;/P&gt;&lt;P&gt;http://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/867-cisco-router-site-to-site-ipsec-vpn.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In access list you need to include your Lan subnets&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 09:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629418#M196135</guid>
      <dc:creator>rakeshvelagala</dc:creator>
      <dc:date>2015-03-13T09:46:13Z</dc:date>
    </item>
    <item>
      <title>Hi. It's not that easy to</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629419#M196136</link>
      <description>&lt;P&gt;Hi. It's not that easy to assist you with VPN config, because there are different levels of encryption, hashing and authentication which you must decide on what works best for your organization. What I can ell you is, in ASDM there is a very "easy to follow" &lt;STRONG&gt;site to site vpn wizard. &lt;/STRONG&gt;If I was you I would give that a shot and come back if it doesn't work. Believe me.......... it's a wizard........ and it's not difficult. Just make sure you define your &lt;STRONG&gt;LAN subnets &lt;/STRONG&gt;correctly on both ASAs (they will be opposite on each ASA) and your&lt;STRONG&gt; peer address&amp;nbsp;&lt;/STRONG&gt;(they will be opposite on each ASA).&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 17:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629419#M196136</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-03-13T17:33:03Z</dc:date>
    </item>
    <item>
      <title>Hi Machi, What is your both</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629420#M196137</link>
      <description>&lt;P&gt;Hi Machi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is your both ASAs'&amp;nbsp;IOS version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2015 00:26:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629420#M196137</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2015-03-15T00:26:42Z</dc:date>
    </item>
    <item>
      <title>Hello, That is 9.1(3)Thanks!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629421#M196138</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is 9.1(3)&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2015 03:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629421#M196138</guid>
      <dc:creator>Machi Ma</dc:creator>
      <dc:date>2015-03-15T03:09:59Z</dc:date>
    </item>
    <item>
      <title>Here is one side</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629422#M196139</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Here is one side configuration example.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# crypto ikev1 policy 1&lt;BR /&gt;hostname(config-ikev1-policy)# authentication pre-share&lt;BR /&gt;hostname(config-ikev1-policy)# encryption 3des&lt;BR /&gt;hostname(config-ikev1-policy)# hash sha&lt;BR /&gt;hostname(config-ikev1-policy)# group 2&lt;BR /&gt;hostname(config-ikev1-policy)# lifetime 43200&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# crypto ikev1 enable outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# crypto ikev2 policy 1&lt;BR /&gt;hostname(config-ikev2-policy)# encryption 3des&lt;BR /&gt;hostname(config-ikev2-policy)# group 2&lt;BR /&gt;hostname(config-ikev12-policy)# prf sha&lt;BR /&gt;hostname(config-ikev2-policy)# lifetime 43200&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# crypto ikev2 enable outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# crypto ipsec ikev1 transform-set FirstSet esp-3des esp-md5-hmac&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# crypto ipsec ikev2 ipsec-proposal secure&lt;BR /&gt;hostname(config-ipsec-proposal)# protocol esp encryption 3des aes des&lt;BR /&gt;hostname(config-ipsec-proposal)# protocol esp integrity sha-1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# access-list l2l_list extended permit ip 192.168.0.0 255.255.0.0 150.150.0.0 255.255.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# tunnel-group 221.222.223.224&amp;nbsp;type ipsec-l2l&lt;BR /&gt;hostname(config)# tunnel-group 10.10.4.108 ipsec-attributes&lt;BR /&gt;hostname(config-tunnel-ipsec)# ikev1 pre-shared-key YourPasswordGoesHere&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# crypto map abcmap 1 match address l2l_list&lt;BR /&gt;hostname(config)# crypto map abcmap 1 set peer 10.10.4.108&lt;BR /&gt;hostname(config)# crypto map abcmap 1 set ikev1 transform-set FirstSet&lt;BR /&gt;hostname(config)# crypto map abcmap 1 set ikev2 ipsec-proposal secure&lt;BR /&gt;hostname(config)# crypto map abcmap interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# route outside&amp;nbsp;150.150.0.0 255.255.0.0 xxx.xxx.xxx.xxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)#&amp;nbsp;object-group network og-local-lan&lt;BR /&gt;hostname(config)# &amp;nbsp;network-object 192.168.0.0 255.255.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# &amp;nbsp;object-group network og-remote-lan&lt;BR /&gt;hostname(config)# &amp;nbsp;network-object 150.150.0.0 255.255.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)#&amp;nbsp;nat (inside,outside) source static og-local-lan og-local-lan destination static og-remote-lan og-remote-lan no-proxy-arp route-lookup&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;hostname(config)# write memory&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;- - - - - - - - - - - -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;xxx.xxx.xxx.xxx = equal to default gateway address on your ASA is using, which is pointing ISP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;This public IP:&amp;nbsp;221.222.223.224, just an example but you use each other's ASA's public address in the place of tunnel-group address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;For the other ASA configuration follows exactly the same and&amp;nbsp;you need to reverse the internal lan. &amp;nbsp;You use your lan subnet need access to other side's local subnet in reverse side.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;access-list l2l_list extended permit ip 150.150.0.0 255.255.0.0&amp;nbsp;192.168.0.0 255.255.0.0&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2015 14:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-setup-where-lan-not-directly-connected/m-p/2629422#M196139</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2015-03-15T14:10:37Z</dc:date>
    </item>
  </channel>
</rss>

