<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec tunnels between duplicate LAN Subnets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418593#M308390</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need you help connecting three sites with our Central site having all the resources for the users including internet access.&lt;/P&gt;&lt;P&gt;All three sites will have the ASA 5505 as their WAN device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to know is this possible, for configuring an IPsec Tunnel Between all three ASA's with Duplicate LAN Subnets.&lt;/P&gt;&lt;P&gt;Central Site two networks 192.168.1.x /24, 192.168.100.x /24&lt;/P&gt;&lt;P&gt;Remote One subnet 192.168.1.x /24&lt;/P&gt;&lt;P&gt;Remote Two one subnet 192.168.100.x /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If above is possible we also need to do Hair pinging from Remote One, Remote Two to the Central Site for internet access, everything both sites need are located at the Central Site, including e-mail, network folders, other resource too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have no other way for doing this network, as all security is located at our Central Site, for Website filtering, Application filtering, all network traffic filtering.&lt;/P&gt;&lt;P&gt;We understand we can change both Remote sites to a different subnet from the Central Site but we have so many host devices this will take weeks or months to complete, along with changing the MS AD Domain for all end users, Servers too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We really need your expertise for doing this in a lab then into production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:08:41 GMT</pubDate>
    <dc:creator>Stephen Sisson</dc:creator>
    <dc:date>2019-03-12T03:08:41Z</dc:date>
    <item>
      <title>IPSec tunnels between duplicate LAN Subnets</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418593#M308390</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need you help connecting three sites with our Central site having all the resources for the users including internet access.&lt;/P&gt;&lt;P&gt;All three sites will have the ASA 5505 as their WAN device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to know is this possible, for configuring an IPsec Tunnel Between all three ASA's with Duplicate LAN Subnets.&lt;/P&gt;&lt;P&gt;Central Site two networks 192.168.1.x /24, 192.168.100.x /24&lt;/P&gt;&lt;P&gt;Remote One subnet 192.168.1.x /24&lt;/P&gt;&lt;P&gt;Remote Two one subnet 192.168.100.x /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If above is possible we also need to do Hair pinging from Remote One, Remote Two to the Central Site for internet access, everything both sites need are located at the Central Site, including e-mail, network folders, other resource too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have no other way for doing this network, as all security is located at our Central Site, for Website filtering, Application filtering, all network traffic filtering.&lt;/P&gt;&lt;P&gt;We understand we can change both Remote sites to a different subnet from the Central Site but we have so many host devices this will take weeks or months to complete, along with changing the MS AD Domain for all end users, Servers too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We really need your expertise for doing this in a lab then into production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:08:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418593#M308390</guid>
      <dc:creator>Stephen Sisson</dc:creator>
      <dc:date>2019-03-12T03:08:41Z</dc:date>
    </item>
    <item>
      <title>IPSec tunnels between duplicate LAN Subnets</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418594#M308392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IF you configure NAT then yes, but I would suggest to move this ticket to the VPN queue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 20:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418594#M308392</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-22T20:31:25Z</dc:date>
    </item>
    <item>
      <title>IPSec tunnels between duplicate LAN Subnets</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418595#M308394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 20:35:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418595#M308394</guid>
      <dc:creator>Stephen Sisson</dc:creator>
      <dc:date>2013-11-22T20:35:41Z</dc:date>
    </item>
    <item>
      <title>IPSec tunnels between duplicate LAN Subnets</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418596#M308395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You know that you can move the post to a VPN queue right???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Nov 2013 05:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418596#M308395</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-23T05:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnels between duplicate LAN Subnets</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418597#M308396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As jumora has mention, you can do this by using NAT.&amp;nbsp; Setup a different subnet for each site and NAT to that subnet. Then create a crypto ACL that specifies the local LAN as the source and the NATed subnet as the destination.&amp;nbsp; This must be done at each site.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The down side to this is that if you are using FQDNs to access servers/PCs at each site, then you would need to create static DNS entries for each new NATed server IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Nov 2013 20:21:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418597#M308396</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-11-23T20:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnels between duplicate LAN Subnets</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418598#M308397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depending on your ASA version the commands will be different, but concept is the same.&amp;nbsp; Have a look at this link to get an idea on how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b37d0b.shtml" rel="nofollow"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b37d0b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Nov 2013 20:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418598#M308397</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-11-23T20:25:03Z</dc:date>
    </item>
    <item>
      <title>IPSec tunnels between duplicate LAN Subnets</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418599#M308398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are currently working on this in our lab, thank you for the documentation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 16:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnels-between-duplicate-lan-subnets/m-p/2418599#M308398</guid>
      <dc:creator>Stephen Sisson</dc:creator>
      <dc:date>2013-11-25T16:15:27Z</dc:date>
    </item>
  </channel>
</rss>

