날짜: 11-26-2014 07:58 AM
Hi All,
I've got two sites connected through a site to site vpn. Everything is working fine but i would like to pass all the internet traffic (www mostly) from the asa in the main office instead using the branch office internet.
The internal network in main office (site A) is 172.17.0.0/16 and in the branch office (site B) is 172.18.0.0/16
Can you please help?
Thank you!
날짜: 11-26-2014 08:55 AM
Instead of reconfiguring your VPN, have you thought about setting up a proxy server in the main office and use that for at least the surf traffic?
For reconfiguring the VPN, you need to
날짜: 11-26-2014 06:21 PM
Hi Karsten,
Thanks, that would be at the end of the project, but right now I cannot do this.
Can you please explain better? I'm not very familiar with crypto maps ...
Thanks!
날짜: 11-27-2014 12:07 AM
More on crypto-maps (and the used IPsec VPNs in general) can be found in the config-guide:
First start with a "show run crypto map". There you find a "match address". In this ACL you need to change the definition to the above mentioned.
Although it won't work without step 2) and 3), you can see the new VPN tunnel with "show vpn-sessiondb det l2l".
새로운 아이디어를 발견하고 저장하세요. 전문가 답변, 단계별 가이드, 최근 주제 등 다양한 내용을 확인해 보세요.
처음이신가요? 아래 팁들을 확인해 보세요. 시스코 커뮤니티 사용하기 새 멤버 가이드