Solved

LAN To LAN VPN between 3005 Concentrator and Netscreen

Posted on 2008-10-03
2
337 Views
Last Modified: 2012-08-14
VPN Tunnel is up between sites however some ip address are not pingable behind the 3005 Concentrator  side ... 10.9.2.x network .


Network:
Edge Router: - (switch where outside concentrator resides) PIX- Core Switch


Pix Firewall
ip address outside 172.16.1.2 255.255.255.0 ( Nat from edge router)
ip address inside 10.9.2.160 255.255.255.0
ip address dmz 192.168.1.254 255.255.255.0
route outside 0.0.0.0 0.0.0.0 172.16.1.1 1
route inside 10.9.1.0 255.255.255.0 10.9.2.223 1
route inside 10.9.6.0 255.255.255.0 10.9.2.160 1
route inside 10.10.1.0 255.255.255.0 10.9.2.223 1
route inside 10.10.0.0 255.255.0.0 10.9.2.223 1

Concentrator

Outside
2xx.xxx.xxx.xxx
inside :10.9.1.15


Core Switch

interface Vlan1
 ip address 10.9.2.223 255.255.255.0
 ipx network 1560B encapsulation SAP
!
interface Vlan2
 ip address 10.9.1.1 255.255.255.0
!
interface Vlan3
 ip address 10.10.3.254 255.255.255.0
!
interface Vlan6
 ip address 10.9.6.1 255.255.255.0
 ipx network 1560C encapsulation SAP
!
interface Vlan7
 ip address 10.10.1.1 255.255.255.0
!
interface Vlan4090
 ip address 20.20.1.1 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 10.9.2.160
ip route 10.9.1.0 255.255.255.0 Vlan2
ip route 10.9.3.0 255.255.255.0 10.9.2.160
ip route 10.9.6.0 255.255.255.0 Vlan6
ip route 10.10.0.0 255.255.0.0 10.9.1.15
ip route 10.10.3.0 255.255.255.0 Vlan3


I can hit everything from my Side 10.10.0.0 to 10.9.1.0
I can hit 10.9.2.223 ( but nothing else unless we place route add statements on the window boxes in the 10.9.2.x network)

Regards


0
Comment
Question by:cogit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 22640577
I would bet that the default gateway for 10.9.2.x hosts = PIX firewall and not the L3 core switch?
You have to change their default to 10.9.2.223.

BTW, never add static routes to directly connected networks. The device is smart enough to know what is connected where
ip route 10.9.1.0 255.255.255.0 Vlan2 <== not necessary
ip route 10.9.6.0 255.255.255.0 Vlan6
ip route 10.10.3.0 255.255.255.0 Vlan3
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month7 days, 13 hours left to enroll

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question