cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
254
Views
0
Helpful
1
Replies

VPN 3000 in single DMZ

stuart.christie
Level 1
Level 1

Hi,

Is it possible to either connect both the public and private interfaces of a VPN 3000 Concentrator to a single DMZ subnet, or to use the concentrator with only one interface connected? (Irrespective of whether either is a good idea!)

Thanks

Stuart

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

The concentrator does support one-armed tunnelling, no problem. Use the Private interface of the concentrator for this rather than the Public. This doesn't work for LAN-to-LAN tunnels (only remote VPN clients), you also lose IPsec over TCP and load-balancing features. Not a recommended solution but certainly does work.

You couldn't really connect up both interfaces to a single DMZ cause that would imply both interfaces have to be in the same subnet, which is not supported.