Question

Cisco, PIX, 800 series router, IP Phone, 501, 857, 7960, CCM on separate range to data LAN, Remote, VPN

Asked by: davebartlett123

I have a site with a data network 11.11.11.x and a phone network (Cisco) 10.1.10.x.  Users at this site plug a phone into a POE switch and get a 10.1.10.x network.  A Pix 501 is providing NAT/VPN/Firewall services on 11.11.11.1 and several VPN connections from Cisco 857 devices terminate here.
The remote networks are 10.2.1.x, 10.2.2.x and 10.2.3.x
The goal is to allow the VPN tunnel to pass voice and data traffic from both networks for remote users.
The VPN's are in place to the networks above and work fine.  I am unsure as to route to and from these networks, I have tried adding this IPSec rule allowing the 10.1.10.x network

access-list 102 permit ip 10.2.2.0 0.0.0.255 10.1.10.0 0.0.0.255

Cant figure out how to get the 837 (remote) to route 10.1.10.x traffic over the VPN let alone get a phone to talk to CCM.

I'm sure its simple but can't see the wood for the trees.

Many thanks

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2008-05-09 at 09:42:38ID23390068
Tags

Cisco

,

PIX, 800 series router, IP Phone

,

501, 857, 7960

,

CCM on separate range to data LAN

Topics

Cisco PIX Firewall

,

Voice Over IP

,

Network Routers

Participating Experts
2
Points
250
Comments
20

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Cisco Pix IPSec VPN
    Hi, I have this problem I hope someone is able to answer me. Over here on the company we use a router and a pix firewall the setup is as follows: || INTERNET ||----|| Router ||----|| PIX ||----|| LAN || Everything is well. We have internet from the inside -> out. Our w...
  2. VPN on PIX
    Is the following configuration on the PIX 6.1 enough to configure VPN . The PIX connects to a catalyst switch on the inside and ISP router on the outside. Do I have to add something to the catayst as well to configure vpn access. ip local pool vpnpool 192.168.1.1-192.168....
  3. pix to pix vpn question
    I've done several router to router vpn tunnels but never pix to pix. Usually to test vpn connectivity from router to router I do an extended ping. Is there something similar I can do on a pix to send ipsec traffic from one to the other?
  4. Cisco PIX IPSec VPN tunnel question
    hi, I would like to set up the VPN IPSec tunnels between two PIXes. 10.0.2.0 and 10.1.8.0 network. I want users from 10.0.2 network able to connect to 10.1.8 network but blocking anyone from 10.1.8 network coming into 10.0.2. Is it possible to do so? Any help is deeply...
  5. Pass Client to Site IPSec VPN Tunnell Through Pix 6.3x
    I am trying to allow a client to site VPN tunnell through a PIX Firewall (version 6.3x). Can anyone shed any light?

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: FaithShieldPosted on 2008-05-09 at 19:06:13ID: 21537564

I'm a little confused as to the layout of your network.

This is what I understood so far.

You have a host site, with CCM, and a PIX firewall, that has a data network of 11.11.11.x and a voice network of 10.1.10.x.  

You have 857 routers at remote sites that are connected over VPN to the 501.

The data portion of the VPN is working fine, but you want to also add phones at the remote sites and have them connect to CCM at the host.

If all of that is true, then you have two issues to overcome.

1.  You must add the voice subnet to the VPN.  This is done by adding an entry to the nat 0 acl on the pix, and the crypto map acl on the pix, that matches traffic from the host voice subnet 10.1.10.x to the remote subnet.  Since you have multiple 857's you will have to edit multiple access lists.  On the remote sites you will also have to adjust the crypto map acl's and the access lists that prevent traffic from translations.

2.  In order for the phones at the remote sites to see call manager you need to add the TFTP server option to your DHCP scope.  if it is done on the 857 it is rather simple just go into the dhcp scope and add the command "option 150 10.1.10.x" , but put the ip address of call manager.

This is the best I can do without seeing your configs.  If you want to post sanitized configs I can look at them.  I need one 857 config and the PIX 501 config.

 

by: davebartlett123Posted on 2008-05-10 at 03:46:06ID: 21538447

Thanks for the quick response, I'll apply what has been suggested and get back to you.

Dave

 

by: davebartlett123Posted on 2008-05-10 at 06:31:57ID: 21538988

Ok, I have amended ACL's at the 857 end and can ping 10.1.10.252 (second IP assigned to a 11.11.11.0 server for testing traffic flow)

Access list on 857 as follows: (public IP's are 1.1.1.1 to the 11.11.11.0 network, 2.2.2.2 to a separate VPN - 10.2.1.0)

access-list 100 remark --- Outside In ---
access-list 100 remark SDM_ACL Category=17
access-list 100 permit ip 10.1.10.0 0.0.0.255 10.2.2.0 0.0.0.255 log
access-list 100 remark IPSec Rule
access-list 100 permit ip 10.2.1.0 0.0.0.255 10.2.2.0 0.0.0.255
access-list 100 permit udp host 1.1.1.1 any eq non500-isakmp
access-list 100 permit udp host 1.1.1.1 any eq isakmp
access-list 100 permit esp host 1.1.1.1 any
access-list 100 permit ahp host 1.1.1.1 any
access-list 100 permit ip 11.11.11.0 0.0.0.255 10.2.2.0 0.0.0.255
access-list 100 permit udp host 2.2.2.2 any eq non500-isakmp
access-list 100 permit udp host 2.2.2.2 any eq isakmp
access-list 100 permit esp host 2.2.2.2 any
access-list 100 permit ahp host 2.2.2.2 any
access-list 100 permit tcp any any eq 3389
access-list 100 permit tcp any any eq 15555
access-list 100 permit tcp any any eq 554
access-list 100 permit gre any any
access-list 100 permit esp any any
access-list 100 permit tcp any any eq www
access-list 100 permit icmp any any unreachable
access-list 100 permit icmp any any time-exceeded
access-list 100 permit icmp any any echo
access-list 100 deny   ip any any
access-list 101 remark --- 11.11.11.0 network ---
access-list 101 permit ip 10.2.2.0 0.0.0.255 11.11.11.0 0.0.0.255
access-list 101 permit ip 10.2.2.0 0.0.0.255 10.1.10.0 0.0.0.255 log
access-list 102 remark --- 10.2.1.0 network ---
access-list 102 permit ip 10.2.2.0 0.0.0.255 10.2.1.0 0.0.0.255
access-list 110 remark --- NAT ---
access-list 110 deny   ip 10.2.2.0 0.0.0.255 10.1.10.0 0.0.0.255 log
access-list 110 deny   ip 10.2.2.0 0.0.0.255 10.2.1.0 0.0.0.255
access-list 110 deny   ip 10.2.2.0 0.0.0.255 11.11.11.0 0.0.0.255
access-list 110 permit ip 10.2.2.0 0.0.0.255 any
access-list 110 deny   ip any any

The PIX 501 inside interface is 11.11.11.1 and this is connected to the same PoE switch that talks to the phone system.  The PIX does not have a 10.1.10.x inside address.

The 7960 phone now has an IP address and tftp is pointing to 10.1.10.1, just keep getting
Configuring CM List
and then
Opening 10.1.10.1

I can obviously ping the 10.1.10.0 network across the VPN but I don't think it knows where to go to get to the 10.1.10.1 host (CCM).

Any ideas?

Thanks,

Dave

 

by: decoleurPosted on 2008-05-10 at 18:50:44ID: 21541220

it might be best to put a laptop on the voice vlan at the remote site and do some pings and traces to see where it is failing. the interesting bit about the VPN is that you have to deny the voice traffic as interesting at the remote end, and confiure it as legitimate and routable at the main site. Here are the things to look at.

at the remote site, does traffic destined for the ccm go over the vpn, set up a ping and watch the stats on the vpn tunnel, if it is working the rx and tx will match but if one is growing and the other isn't it will help yo uidentify if it is an access issue or a routing issue.

at the main site can you ccm ping to the voice vllan at the remote site, does it route approriately. try to ping the device on the voice vlan at the remote site from the ccm and watch your counters on both sides, are they both incrimenting or is one side not in one direction.

Thinkng about when is required on both sides should help,

I hope this does.

-t

 

by: FaithShieldPosted on 2008-05-11 at 19:15:40ID: 21544302

On the Pix 501, do you have a route to the 10.1.10.0 network?

route (inside) 10.1.10.0 255.255.255.0 11.11.11.x

???

 

by: davebartlett123Posted on 2008-05-12 at 01:24:38ID: 21545297

For some reason, I am unable to ping 10.1.10.1 (CCM) from any machine at the main site.  This is possibly by design, not 100% sure as I didn't install the phone system.  Below are snippets from the CCM config detailing the ethernet interfaces:

controller E1 0/0/0
 pri-group timeslots 1-31
!
class-map match-all L3-to-L2_VoIP-Cntrl
 match ip dscp af31
class-map match-all L3-to-L2_VoIP-RTP
 match ip dscp ef
!
!
policy-map output-L3-to-L2
 class L3-to-L2_VoIP-RTP
  set cos 5
 class L3-to-L2_VoIP-Cntrl
  set cos 3
!
gw-accounting syslog
!
!
!
!
interface GigabitEthernet0/0
 description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$
 no ip address
 no ip mroute-cache
 duplex auto
 speed auto
!
interface GigabitEthernet0/0.100
 encapsulation dot1Q 100
 ip address 10.1.10.1 255.255.255.0
 no snmp trap link-status
 service-policy output output-L3-to-L2
!
interface GigabitEthernet0/0.200
 encapsulation dot1Q 200 native
 ip address 192.168.1.1 255.255.255.0
 no snmp trap link-status

The system as I understand works as follows:

1. Phones work off 10.1.10.0/24 network using TFTP to 10.1.10.1 to download boot file.
2. Stonevoice admin is on 192.168.1.0 network, the phone's DNS server points to this network (192.168.1.15/24 - SBS Server DNS)
3. PC's connect to the 11.11.11.0/24 network but can be plugged into the back of any handset and still get 11.11.11.0/24 DHCP addresses.
4. Remote site (10.2.2.0/24) can now ping 192.168.1.0/24 traffic apart from .1 (internal users can ping)
5. Remote site (10.2.2.0/24) can now ping a dual homed server on 10.1.10.252 but cannot ping 10.1.10.1 (neither can internal users)

Cisco Phone on remote site just waits for CM config.

I think routing is working for 10.1.10.0 and 192.168.1.0 networks over VPN as a tracert shows traffic going directly to specified host.

Bit of a head scratcher!

 

by: decoleurPosted on 2008-05-12 at 03:40:45ID: 21545747

a couple of questions:
from the pix can you ping the CCM?
on the pix is the 10.2.2.0/24 in the no nat statement?
from the CCM can you ping the remote site? look at the vpn statistics on both sides to confirm traffic is making it out and coming back.

hope this helps,

-t

 

by: davebartlett123Posted on 2008-05-12 at 03:45:41ID: 21545762

Thanks decoleur,

I cannot ping CCM from anywhere internally or externally but I can ping 10.1.10.252 (set up for test internally) from the remote 10.2.2.0 site

 

by: decoleurPosted on 2008-05-12 at 03:50:01ID: 21545778

me thinks this is your issue... if the pix canot get to the CCM i cannot see how the remote phones will, it is essentially the local termination of the remote site's vpn.

 

by: davebartlett123Posted on 2008-05-12 at 03:54:06ID: 21545790

Do I need to add a 10.1.10.x address to the PIX?

 

by: decoleurPosted on 2008-05-12 at 04:07:33ID: 21545842

if the routing doesn't exist on your network to allow that sort of traffic then you have to do something, adding 10.1.10.x to an interface or a trunked subinterface would do.

is this the first remote site that you have connected via vpn?

 

by: davebartlett123Posted on 2008-05-12 at 05:23:30ID: 21546203

One of two remote sites.

The PIX 501 does not support trunked subinterfaces from what I understand

I wonder if CCM has ICMP disabled by default as it cannot be reached from anywhere (internal or external) however all internal phones boot an image from it every time.

 

by: decoleurPosted on 2008-05-12 at 08:41:14ID: 21547959

i think yo uare right about the pixes limitations...

So, ping in the other direction, what happens if you ping from the ccm to the working remote site? compare that with what happens when you ping to the non-working remote site.

if you could include clean versions of the running configs for the routers at the working and non working remote sites as well as the pix i think we can move forward.

 

by: FaithShieldPosted on 2008-05-12 at 09:15:09ID: 21548220

Your problem is that you have no route between the router for which you just posted the config and the firewall.  You need to add a trunk sub interface to the router, that is on the same subnet as the PIX firewall and set a route to the remote site that points to the PIX on that router.

See we know that traffic from the remote is getting to the 10.1.10.x subnet.  The issue is that traffic is not getting back.  It works on 10.1.10.252 because that server is dual homed and it has another interface on the data network, where its default route resides.  So it is sending its return traffic not to 10.1.10.1, but to the data subnet default gateway.

I will assume that the DATA or the 11.11.11.x network is on VLAN 1, because you have not provided that info.


Assumptions :

VLAN 1 is your 11.11.11.x subnet
11.11.11.2 is available for use on your router.
The CCM Server is pointing to 10.1.10.1 as its default gateway.

Add this to your router...


interface GigabitEthernet0/0.1
 encapsulation dot1Q 1
 ip address 11.11.11.2 255.255.255.0
 no snmp trap link-status
!

ip route 10.2.2.0 255.255.255.0 11.11.11.1



 

 

by: davebartlett123Posted on 2008-05-15 at 01:31:14ID: 21571537

Ok, here's where we are.

Cisco 2821 interfaces configured as follows:

interface GigabitEthernet0/0
 description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$
 no ip address
 no ip mroute-cache
 duplex auto
 speed auto
!
interface GigabitEthernet0/0.100
 encapsulation dot1Q 100
 ip address 10.1.10.1 255.255.255.0
 no snmp trap link-status
 service-policy output output-L3-to-L2
!
interface GigabitEthernet0/0.200
 encapsulation dot1Q 200 native
 ip address 192.168.1.1 255.255.255.0
 no snmp trap link-status
!
interface GigabitEthernet0/0.300
 encapsulation dot1Q 1
 ip address 11.11.11.2 255.255.255.0
 no snmp trap link-status
!
interface GigabitEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface Serial0/0/0:15
 no ip address
 encapsulation hdlc
 isdn switch-type primary-net5
 isdn incoming-voice voice
 no cdp enable
!
ip route 10.2.2.0 255.255.255.0 11.11.11.1

From 10.2.2.0 (remote network) I can ping:
11.11.11.2 but not 10.1.10.1
From 2821 I cannot ping 11.11.11.1 or 10.2.2.0 even though subinterface has 11.11.11.2 as configured address.

Cisco phone at remote site is looping through opening 10.1.10.1 - configuring CM list.

What does service-policy output output-L3-to-L2 mean?  This is set on the GigabitEthernet0/0.100 interface.

Why can I ping 11.11.11.2 from the remote network but not back?

Thanks

Dave



 

by: FaithShieldPosted on 2008-05-15 at 19:09:12ID: 21579371

class-map match-all L3-to-L2_VoIP-Cntrl
 match ip dscp af31
class-map match-all L3-to-L2_VoIP-RTP
 match ip dscp ef
!
!
policy-map output-L3-to-L2
 class L3-to-L2_VoIP-RTP
  set cos 5
 class L3-to-L2_VoIP-Cntrl
  set cos 3

That is what the Service policy output L3 to L2 does, it maps DSCP af31 t cos 5 and DSCP ef to cos 3.  It is just a transition of the qos marking from layer 3 DSCP marking to layer 2 COS Marking.  Doesn't really do anything, except let the switch know what traffic is important.

You have to be able to ping 11.11.11.1 from 11.11.11.2.  If you can't do that then your PIX, must not be plugged into VLAN 1 on your switch.

Can you please do a show vlan, and a show int status on the switch and then tell us what ports the pix and router are connected to.

We need the interface that has 11.11.11.1 to be in the same vlan as the PIX.  I am starting to think that you have two subnets overlapping on the same VLAN, which is not a good design, but we could still make this work if we move the 11.11.11.1 to a secondary interface on the 100 vlan.

Do you know if the what VLAN the PIX is connected to?

 

by: davebartlett123Posted on 2008-05-16 at 04:20:51ID: 21581760

I have attached a visio diagram of the network, hopefully this should clarify the configuration.

Many thanks

 

by: FaithShieldPosted on 2008-05-16 at 06:09:39ID: 21582325

Hmm.

Remove the 11.11.11.2 from the trunk'd vlan 1 interface on the 2821, and put it on GIG0/1.

Then plug GIG 0/1 into the 4 port switch in the back of the PIX 501.

The CE500 is very likely your issue.  Those things are horrible.  They turn on all kinds of anti-spoofing and arp suppression and if you use the smart port configs which you probably did, then they wreak havok on trying to get things to work at all.

They have access to the command line through http://switchip/exec

If you are familiar with switch command line, then I suggest you go spend 6-8 hours in that exec interface cleaning things up.  If not then you might be better served getting a 2960 switch with POE to replace the CE500.

There really is no way for us to troubleshoot all the things that could be wrong with that CE500 over this forum.  But if you plug your Gig 0/1 directly into the firewall's switch, then you essentially bypass all that nonsense.  I really don't know why it is that you can ping 11.11.11.2 on the 501, and still not get to 10.1.10.1, except that the CE500 must somehow be messing it up.

 

by: davebartlett123Posted on 2008-05-20 at 01:54:47ID: 21604420

Faith Shield,

On the money!

Cabled GIG 0/1 and assigned IP 11.11.11.2, all is sweet!

Many thanks for your help!

Dave

 

by: davebartlett123Posted on 2008-05-20 at 01:55:36ID: 31456574

Many thanks!

Dave

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...