<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: STS TUNNEL SETUP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308873#M343518</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ray,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure whether i understood your requirement correctly but this what i understood that your remote site have a loadbalancer with 2 ISP to share the load.&amp;nbsp; The firewall's outside interface has a private IP which is connected on the inside of the LB and LB is doing the NATTING. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunatley VPN doesn't work with Load balacing. &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jeet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Sep 2013 03:14:10 GMT</pubDate>
    <dc:creator>Jeet Kumar</dc:creator>
    <dc:date>2013-09-06T03:14:10Z</dc:date>
    <item>
      <title>STS TUNNEL SETUP</title>
      <link>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308868#M343510</link>
      <description>&lt;P&gt;Hello Experts,&lt;BR /&gt;&lt;BR /&gt;We need to create a STS tunnel with one of our client and they have the load balancer in front of their firewall and two ISP link are terminated on load balancer and load balance internal network is connected with firewall. Firewall interface which is connected with LB has private IP address assigned which is acting as a wan port and firewall has one internal face configured where the servers are placed so there are two natting here -one is at the firewall and second one is on LB. LB has the natting configured with public IPs of ISPs and both ISPs IP being terminating on LB -not on firewall. Now we need to establish a STS tunnel with client firewall where the public not being terminated so it possible that the private IP of outside interface of firewall I do the nat on LB with public IP and then create a tunnel on firewall. Would it work? Please explain in details if it works or not.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308868#M343510</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2019-03-12T02:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: STS TUNNEL SETUP</title>
      <link>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308869#M343511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can somebody response on this ?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 11:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308869#M343511</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2013-09-05T11:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: STS TUNNEL SETUP</title>
      <link>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308870#M343514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ray,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it should work if you do one to one NAT on loadbalancer with a public IP to private IP of the firewall outisde interface and having a rule that should allow the required traffic to the firewall outside IP or any any rule set for the NAT. i.e. which should not block any traffic towards the firewall outside IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client end (Public IP) --&amp;gt; ISP --&amp;gt;&amp;nbsp; LB(Public to Private IP NAT towards firewall Interface) --&amp;gt; ASA(configured with the private IP as its outside &amp;amp; VPN peer ip as it is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me go through some scenarios and possibly can confirm you on the same...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 12:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308870#M343514</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2013-09-05T12:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: STS TUNNEL SETUP</title>
      <link>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308871#M343515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please confirm if it works. I tested out this but unfortunately it's not working.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 13:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308871#M343515</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2013-09-05T13:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: STS TUNNEL SETUP</title>
      <link>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308872#M343517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can somebody please provide more inputs on this.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 01:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308872#M343517</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2013-09-06T01:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: STS TUNNEL SETUP</title>
      <link>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308873#M343518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ray,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure whether i understood your requirement correctly but this what i understood that your remote site have a loadbalancer with 2 ISP to share the load.&amp;nbsp; The firewall's outside interface has a private IP which is connected on the inside of the LB and LB is doing the NATTING. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunatley VPN doesn't work with Load balacing. &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jeet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 03:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sts-tunnel-setup/m-p/2308873#M343518</guid>
      <dc:creator>Jeet Kumar</dc:creator>
      <dc:date>2013-09-06T03:14:10Z</dc:date>
    </item>
  </channel>
</rss>

