cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
311
Views
0
Helpful
1
Replies

Routing between the vpn tunnels

zeuscyril
Level 4
Level 4

Hi

I have central office having 2811 vpn router and the 2 outlets having a point to point tunel to the central office,

Both the tunels are active at the central office, and can comunicate from central office to the outlets and viceversa, but not able to comunicate betwee the outlets.

Central Office LAN- 10.60.101.0/24

Outlets A LAN===========10.60.102.0/24

Outlet B LAN============ 10.200.1.0/24

Crypto acceslist at Central

Extended IP access list 100(Outlet B 2 Central)

10 permit ip 10.60.96.0 0.0.15.255 10.192.0.0 0.31.255.255

Extended IP access list 102 (Central to Outlet A)

10 permit ip 10.60.96.0 0.0.15.255 10.60.102.0 0.0.0.255

20 permit ip 10.192.0.0 0.31.255.255 10.60.102.0 0.0.0.255

Is this acces list enough to route the network from Outlet A to Outlet B thru Central office?

1 Reply 1

andrew.prince
Level 10
Level 10

You need to ensure that the two subnets are exempt from your NAT, and they are in the encryption domains acls at all 3 sides.

HTH>