11-07-2021 05:16 AM
Hello Experts,
So i have asked by my customer that is it possible to form s2s vpn using local ip interface?
What i mean is that usually, i configure and form s2s vpn using fw/router that directly faced to the internet, for example from the picture below i usually config crypto map on "Router 0" on its internet-facing interface that using ip public, which is interface gi0/0/0 (ip public : 103.45.43.2).
Is it possible to form s2s vpn from internal router and internal ip and internal interface which is "Router 2" with its gi0/0/0 interface and its ip private is 192.168.1.10? So i want to form s2s vpn between {Router 2, Gi0/0/0, 192.168.1.10} to {Router 3, Gi0/0/0, Ip public 201.23.4.3}. Is it possible? Btw the Router 2 private ip address is natted to ip public 103.45.43.10 on router 0.
The s2s vpn is not between cisco router, i disguise the pictures below because of customer;s credentials. But there is cisco devices between them.
11-07-2021 05:22 AM
@Ilhams Yes. You just need to configure Router3 to set the peer as the NAT IP address (103.45.43.10) of Router 2.
On Router 2 setup the peer using the Public IP address (201.23.4.3) of Router 3.
11-07-2021 05:27 AM
yes possible as long as they are NAT and visible to external.
Make sure the below ports are allowed.
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide