<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN for overlapping networks in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151651#M860656</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you configured the crypto acl that matches the natt'd IP addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the remote end configured to accept the encryption domain of the natt'd IP addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Apr 2009 12:17:48 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2009-04-22T12:17:48Z</dc:date>
    <item>
      <title>VPN for overlapping networks</title>
      <link>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151650#M860655</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having problem with VPN setup for overlapping network scenario on PIX 525 running 6.3(4) OS with unrestricted licence. I tried to use first PAT then standard static translation to hide the 192.168... network on vpn initiating network. With continous ping running I can see hits incrementing on all relevant access lists (including crypto map access-list) but debug crypto isakmp output shows nothing for this particular vpn but displays output when other vpns get built. I checked all obvious things like ping getting to inside interface and via inside in access-list, routing, nat 0, access-list for other vpns (to see if traffic gets routed down other tunnels) but no joy.&lt;/P&gt;&lt;P&gt;Anyone has seen no output debug scenario before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Andrew&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:21:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151650#M860655</guid>
      <dc:creator>andrew.fedyszak</dc:creator>
      <dc:date>2019-03-11T15:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN for overlapping networks</title>
      <link>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151651#M860656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you configured the crypto acl that matches the natt'd IP addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the remote end configured to accept the encryption domain of the natt'd IP addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2009 12:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151651#M860656</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-04-22T12:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN for overlapping networks</title>
      <link>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151652#M860657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for replaying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the crypto access list includes NATed address as a source and remote end is configured correctly.&lt;/P&gt;&lt;P&gt;I can see hit count on both NAT and crypto access list incrementing with continuos ping running from a host behind "vpn initiator" peer (PIX 525).&lt;/P&gt;&lt;P&gt;My problem is that there is no output from "debug crypto isakmp" command for this vpn (output is displayed for other 20 vpns on this PIX???), so I assume that no isakmp packets for phase 1 are generated by vpn initiating PIX (I can see no packets when running "debug packet outside dst &lt;MY pix="" vpn="" peer="" address=""&gt; both" command.&lt;/MY&gt;&lt;/P&gt;&lt;P&gt;The "show xlate | include 13.0.0.1" command output shows my local to global mapping correctly, so NAT seems to work. I can see hit count on crypto map access list increasing with every ping packet coming, so (I think):&lt;/P&gt;&lt;P&gt;1) routing sends PATed packet to outside interface (otherwise crypto map "relevant traffic" access-list would not come into play).&lt;/P&gt;&lt;P&gt;2) crypto map should pick up the "request" to bring up vpn, but no isakmp packets are generated.&lt;/P&gt;&lt;P&gt;I had 10 years of mainframe (Tandem) experience and I have never before seen mainframe debug failing to generate output.&lt;/P&gt;&lt;P&gt;It is difficult to fault find if key tool does not show anything ;-(&lt;/P&gt;&lt;P&gt;I even changed the config to use static (inside, outside) etc translation, but again there is no output from debug although xlate and crypto map access-list behave correctly.&lt;/P&gt;&lt;P&gt;are there any known gotchas with either PIX 6.3(4) routing or PATing which would result in this behaviour?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks and regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2009 13:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151652#M860657</guid>
      <dc:creator>andrew.fedyszak</dc:creator>
      <dc:date>2009-04-22T13:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN for overlapping networks</title>
      <link>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151653#M860658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you tried a higher level of debug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto isakmp 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2009 20:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-for-overlapping-networks/m-p/1151653#M860658</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-04-22T20:28:27Z</dc:date>
    </item>
  </channel>
</rss>

