01-19-2017 11:05 PM - edited 02-21-2020 09:07 PM
As title states.... does anyone have any configuration examples to run L2TPv3 to tunnel and extend L2 over an IPsec L3 site-to-site tunnel ?
Solved! Go to Solution.
01-31-2017 12:36 AM
The router! L2TPv3 doesn't run on Windows in this scenario
01-31-2017 12:47 AM
Right.. Got you. Let's forget about the differing, and simultaneous VPN profiles and configurations on IOS .. and whether that will work or not.
What about the L2 extension .. That won't work with RA SSL VPN to workstation, right ?
Unless IOS can proxy-arp ? Thoughts/comments here ?
01-31-2017 12:52 AM
Please give me some time to extend my lab, I'll try to reproduce this setup here with some more machines.
01-31-2017 01:39 AM
Take your time. You're a good man. Would appreciate what you can emulate and report back on. Thanks !
02-01-2017 01:31 AM
Hi,
I dindn't get it to work. I was able to dial in via VPN and got an IP address of the local LAN but the there was no visible traffic on the VPN adapter on the client.
So I'd say you need a separate machine in the DC where clients can login (or as you said a jumphost).
Also I don't think this will work with an 829 on the edge since you need 2 real routed ports for L2TPv3.
02-01-2017 04:12 AM
Right.....
http://www.cisco.com/c/en/us/products/collateral/routers/829-industrial-router/datasheet-c78-734981.html
Screenshot here - http://i.imgur.com/JkuJ6AH.png
Yes.. and only 4 x SWITCHports are on the device..
So it's not very accurate to state the 829 IR can do LTPv3 VPN then.. really...
I don't necessarily mind I can't extend the MAC of the workstation over RA SSL VPN with AnyConnect.. What I do have an issue with is not even able to get the LTPv3 working now.. from what you're telling me.. because of lack of L3 ports on the 800 series ?
02-01-2017 04:53 AM
Sorry, I double-checked it right now with SVI and it works.
It works since IOS 12.4.20(T), definately with 829!
But beware that VLAN1 (SVI) is not allowed to have an IP address:
R1(config)#int vl1
R1(config-if)#ip add 10.0.0.1 255.255.255.0
Incompatible with xconnect command on Vl1 - command rejected.
02-01-2017 05:23 AM
< big thumbs up and a thankyou >
Legend !
02-03-2017 12:42 AM
http://www.cisco.com/c/en/us/support/docs/field-notices/642/fn64252.html
02-03-2017 02:11 AM
eek! Appreciate that ciscomax . Thanks for sharing that.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide