06-11-2020 07:32 AM
Hey, I have a Cisco Router 2821 (Cannot replace with ASA or anything else). I'm doing a project where I'm trying to set up a client-site VPN for remote access to just one server. The networking setup I have so far is the following:
Server -> VPN Router (can add a switch between if needed)
VPN Router -> Switch (added port security etc, but unsure if the switch is best placed here or between server/VPN router)
Switch -> ISP Port
I have a public address availble and have a rough sanitized config which is attached. I can only use older versions of Cisco AnyConnect and the Cisco VPN client.
Here are my questions:
1. Is this sanitized configuration correct?
2. Is the design of the networking equipment correct?
3. Do I need to add the public address to the outside port of the VPN Router or do I make it an internal IP?
4. Do I need to do any port forwarding?
Thank you for any and all help.
Here's a rough guide I used to get started. http://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/809-cisco-router-vpn-client.html
I realize this didn't cover the ISP router issue, so that's my biggest dilemma.
06-11-2020 08:14 PM
06-12-2020 07:55 AM
06-12-2020 10:23 AM
There are some things that are not clear to me and I would appreciate some clarification. My understanding of the original post was that this was to be a Remote Access VPN to allow a client to access a single server. What I am seeing in the revised config recently posted looks more like site to site VPN (especially with interface Virtual-Template2 type tunnel). Are we aiming for site to site or Remote Access?
If it is to be Remote Access then what client do you plan to use? There is not anything in the config about enabling AnyConnect and there is some configuration for isakmp client. Does this suggest that you are planning to use the old Cisco VPN client which used IPSEC? Or something else? The Cisco VPN client is quite old, is not supported any more, and I believe that it has problems running under several modern OS. I would think you would be better off using AnyConnect.
06-15-2020 05:45 AM
06-15-2020 11:17 AM
This link has information that I hope you will find helpful about configuring AnyConnect on an IOS router.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide