LAN To LAN VPN between 3005 Concentrator and Netscreen

Posted on 2008-10-03
Last Modified: 2012-08-14
VPN Tunnel is up between sites however some ip address are not pingable behind the 3005 Concentrator  side ... 10.9.2.x network .

Edge Router: - (switch where outside concentrator resides) PIX- Core Switch

Pix Firewall
ip address outside ( Nat from edge router)
ip address inside
ip address dmz
route outside 1
route inside 1
route inside 1
route inside 1
route inside 1


inside :

Core Switch

interface Vlan1
 ip address
 ipx network 1560B encapsulation SAP
interface Vlan2
 ip address
interface Vlan3
 ip address
interface Vlan6
 ip address
 ipx network 1560C encapsulation SAP
interface Vlan7
 ip address
interface Vlan4090
 ip address
ip route
ip route Vlan2
ip route
ip route Vlan6
ip route
ip route Vlan3

I can hit everything from my Side to
I can hit ( but nothing else unless we place route add statements on the window boxes in the 10.9.2.x network)


Question by:cogit
LVL 79

Accepted Solution

lrmoore earned 500 total points
ID: 22640577
I would bet that the default gateway for 10.9.2.x hosts = PIX firewall and not the L3 core switch?
You have to change their default to

BTW, never add static routes to directly connected networks. The device is smart enough to know what is connected where
ip route Vlan2 <== not necessary
ip route Vlan6
ip route Vlan3

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now