cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
358
Views
0
Helpful
1
Replies

pix to pix vpn question

peter.saldanha
Level 1
Level 1

Hi

I have established pix to pix vpn connectons from 2 branch offices to head office. The head office is a lesed line and both branch offices are a ADSL line which are dynamic IP sites. Now both branch offices can access head office. Can I have a branch to branch connectivity in this scenario via this existing VPN ?

1 Reply 1

gschertz
Level 1
Level 1

Yes you can have remote to remote VPN communications. Your current setup has 2 tunnels one from each remote into the main location. The main location will have one ipsec with both remotes on it. For remote to remote the PEER addressing will be diferent so you will have to set up another tunnel on the remotes for remote to remote communications. Issue here is dynamic IP ? your getting dhcp from the ISP? is so the other option is. And I don't like this one. Is set up the main to allow remote to remote relay. You would need to add lines to the controlling access-list to permit remote 1 ip addressing to remote 2 ip addressing. And remote 2 to remote 1. Then add a static route at each remote pointing to the other through the main location. Also add this combination to the no-nat access-list so traffic remote to remote will not be nated like it was regular internet traffic. But all traffic from remote to remote will then be hairpined off of the main location. Increasing the load on the leased line.