<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem in Site-to-site VPN ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518601#M611723</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having router conncted directly to ISP &amp;amp; Firewall connected to router. I want to configure VPN on ASA Firewall. The LAN traffic is natted to public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router Outside having IP (1.1.1.1/29)&lt;/P&gt;&lt;P&gt;Router Inside having IP (10.0.0.1/29)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall Outside (Connected to router having 10.0.0.2/29)&lt;/P&gt;&lt;P&gt;Firewall inside (Connected to LAN having 172.10.1.1/24)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do nat of public IP 1.1.1.2. i.e i mapped 10.0.0.2 (private address on public ip 1.1.1.2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can i use 1.1.1.2 ip for site-to-site VPN as a peer IP ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to reach specific ports of server as given in my question so how to do that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anything you require just reply me..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Sep 2010 10:19:35 GMT</pubDate>
    <dc:creator>vinayak</dc:creator>
    <dc:date>2010-09-13T10:19:35Z</dc:date>
    <item>
      <title>Problem in Site-to-site VPN ?</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518598#M611720</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having head office &amp;amp; branch office. our servers are at head office having ip address in serise 192.168.1.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to establish site-to-site VPN between these 2 offices. also i want to reach some specific ports of head office server such as :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to reach&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="CA" style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="CA" style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; color: navy; font-size: 10pt; sans-serif&amp;amp;quot: ; mso-ansi-language: CA; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;192.168.1.9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 171&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; color: navy; font-size: 10pt; sans-serif&amp;amp;quot: ; mso-ansi-language: CA; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;192.168.1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 989&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; color: navy; font-size: 10pt; sans-serif&amp;amp;quot: ; mso-ansi-language: CA; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;192.168.1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 989&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; color: navy; font-size: 10pt; sans-serif&amp;amp;quot: ; mso-ansi-language: CA; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;192.168.1.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 85&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; color: navy; font-size: 10pt; sans-serif&amp;amp;quot: ; mso-ansi-language: CA; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;How to do that.??? can anyone help me...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; color: navy; font-size: 10pt; sans-serif&amp;amp;quot: ; mso-ansi-language: CA; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;Thanks...&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518598#M611720</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2019-03-11T18:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in Site-to-site VPN ?</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518599#M611721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having head office &amp;amp; branch office. our servers are at head office having ip address in serise 192.168.1.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to establish site-to-site VPN between these 2 offices. also i want to reach some specific ports of head office server such as :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to reach&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="CA" style="color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN lang="CA" style="color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;192.168.1.9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 171&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;192.168.1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 989&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;192.168.1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 989&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;192.168.1.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 85&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;How to do that.??? can anyone help me...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; color: navy; font-size: 10pt; mso-ansi-language: CA;"&gt;Thanks...&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 09:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518599#M611721</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-13T09:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in Site-to-site VPN ?</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518600#M611722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi vinayak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we can have a site to site vpn, but to proceed any further please brief us more about ur networks and devices and natting that you will be having&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here are the general guide lines&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which ever traffic needs to be encrypted should be identified in crypto acl and should be exempted from natting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you can provide us details about ur devices i can send me appropriate config guides&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 09:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518600#M611722</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-13T09:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in Site-to-site VPN ?</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518601#M611723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having router conncted directly to ISP &amp;amp; Firewall connected to router. I want to configure VPN on ASA Firewall. The LAN traffic is natted to public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router Outside having IP (1.1.1.1/29)&lt;/P&gt;&lt;P&gt;Router Inside having IP (10.0.0.1/29)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall Outside (Connected to router having 10.0.0.2/29)&lt;/P&gt;&lt;P&gt;Firewall inside (Connected to LAN having 172.10.1.1/24)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do nat of public IP 1.1.1.2. i.e i mapped 10.0.0.2 (private address on public ip 1.1.1.2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can i use 1.1.1.2 ip for site-to-site VPN as a peer IP ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to reach specific ports of server as given in my question so how to do that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anything you require just reply me..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 10:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518601#M611723</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-13T10:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in Site-to-site VPN ?</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518602#M611724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can use the ASA fw Public IP on the router (1.1.1.2) as the VPN peer on the HQ side.&lt;/P&gt;&lt;P&gt;On the ASA, configure the crypto ACL with the local provate LAN as your source and destination as the HQ servers (192.168.1.*)&lt;/P&gt;&lt;P&gt;Add route on the ASA fw for 192.168.1.0 towards Outside (Router internal interface IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Router ACL you will have to allow the ports UDP 500, ESP and UDP 1000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 11:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518602#M611724</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2010-09-13T11:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in Site-to-site VPN ?</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518603#M611725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dhananjoy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u please tell me how to allow ports on router ???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 11:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-site-to-site-vpn/m-p/1518603#M611725</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-13T11:20:06Z</dc:date>
    </item>
  </channel>
</rss>

