cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
475
Views
0
Helpful
2
Replies

VPN to 3745 from mobile site via two different networks

nbourke2000
Level 1
Level 1

Hi, wondering if anyone has any ideas on a problem I have.

I have 2 networks, one private and one internet, connecting to 2 interfaces on a 3745 router. I have mobile client routers (netscreens) that are moving from one network to the other.

The problem I have is the tunnel comes up when the client is on internet but when connected via the client network it needs a static route on the PoP pointing to the client network.

Without the static route the SA shows as QM_IDLE but it does not pass traffic. I also have an issue where when the router moves from internet to the private  network the SA stays on the 3745 and causes SPI problems until it clears. Reducing idle-time seems to do nothing to help this.

2 Replies 2

nbourke2000
Level 1
Level 1

I think maybe Reverse Route Injection might be a partial solution?

praprama
Cisco Employee
Cisco Employee

Hi,

So to clarify the problem, we have VPN termination on 2 different interfaces on a 3745, "internet" and "private". When connecting to "internet" all works fine. When connecting to "private", connection is up but no traffic passes unless a static route is added.

Could you elaborate more on what is the exact command you add? It will be much easier to understand if you could post a sanitized config and a topology as well.

Regards,

Prapanch

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: