02-06-2017 03:37 AM - edited 02-21-2020 09:08 PM
Hi
I have an issue to configure a VPN in my local router
The configuration between the two site is OK ,I can access from the local network to the remote HQ network ( I don't have the right to configure the HQ router )
The problem is I need to add a remote VPN client to access remotly from my computer to my local router and then connect to the remote HQ network
Can you please help on how to do this ,knowing that I will split my local subnet ,that I am using for the Ipsec with the HQ , to use it on my remote clients VPN IP pool ,because I can note authorize a new network on the remote HQ (we don't have access )
Thanks
You can find in the image below the topology information
02-06-2017 04:59 AM
I don't think anything more is required for this to work since you don't have a NAT for the traffic from VPN client to remote network. Here is what I see should happen:
1) VPN traffic from client reaches Local Router (LR) and gets decrypted. Since the actual IP headers point to the remote destination, it points destination interface as outside interface.
2) Traffic matches existing crypto rules and goes across the tunnel.
3) Return traffic matches route for destination to outside interface (static route to VPN pool on tunnel establishment) and is sent out via VPN client tunnel.
Does this work for you with the config you have now?
02-07-2017 01:34 AM
Hi Govindan and thank you for the answer . I am using the same interface to establish the tunnel with the HQ router and the VPN client ,and my configuration is not working ,(this is the first time I'm configuring a VPN ,I m only a ccna level )
Do you have any suggestion for this configuration ?
Thanks ,
02-08-2017 09:23 AM
Can you attach a santized config here?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide