Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Remote access VPN and site-to-site VPN connections on one router

Posted on 2008-10-07
7
Medium Priority
?
317 Views
Last Modified: 2012-05-05
Currently have a Cisco 2610 router configured for remote VPN access via the Cisco VPN Client. We would like to also use this same router in a site-to-site VPN scenario to another office. Is it possible to provide both these services with this one router and one public IP address? I thought you could only apply one crypto map to the outside interface?

Below is our current running-config; Thanks for any help.


version 12.3
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname VPNrouter
!
boot-start-marker
boot system tftp c2600-ik9o3s3-mz.123-18.bin 10.200.202.50
boot-end-marker
!
enable secret 5 $1$/uXD$.pXv9eM.XBJYm9cBbiUjd1
!
aaa new-model
!
!
aaa authentication login local local
aaa authorization network VPN local
aaa session-id common
ip subnet-zero
ip cef
!
!
no ip domain lookup
!
ip dhcp pool test
!
ip audit po max-events 100
!
!
!
!
!
!
!
!
username **** password 0 ****
username **** password 0 ****
username **** password 0 ****
username **** password 0 ****
!
!
!
crypto isakmp policy 3
 encr 3des
 authentication pre-share
 group 2
!
crypto isakmp client configuration group ****
 key creatine
 dns 10.200.202.50
 domain xxxx.com
 pool VPNpool
 acl 101
!
!
crypto ipsec transform-set VPN esp-3des esp-md5-hmac
!
crypto dynamic-map dynmap 10
 set transform-set VPN
!
!
crypto map VPNmap client authentication list local
crypto map VPNmap isakmp authorization list VPN
crypto map VPNmap client configuration address respond
crypto map VPNmap 10 ipsec-isakmp dynamic dynmap
!
!
!

interface Ethernet0/0
  ip address 10.200.201.100 255.255.255.0
 ip broadcast-address 0.0.0.0
 half-duplex
 crypto map VPNmap
!
!
ip local pool VPNpool 10.200.203.1 10.200.203.50
ip http server
no ip http secure-server
ip http path flash:
ip classless
ip route 0.0.0.0 0.0.0.0 10.200.201.254
!
access-list 101 permit ip 172.16.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 192.168.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 172.30.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 10.200.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 10.100.0.0 0.0.255.255 10.200.203.0 0.0.0.255
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 exec-timeout 90 0
 password ****
!
!
end
0
Comment
Question by:Italia_NYC
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 22663757
I do this on a Netscreen 5 GT, so I would think that it should work on a Cisco, but it may be device dependent.

0
 
LVL 2

Author Comment

by:Italia_NYC
ID: 22663907
I applaud your effort and participation SysExpert. Unfortunately however, that was not very useful to me.
0
 
LVL 12

Accepted Solution

by:
Pugglewuggle earned 750 total points
ID: 22666114
Yes, you absolutely can setup both site-to-site VPN and remote access VPN on a Cisco router. I do it all the time.
What exactly do you need help with? I see that you've already got remote access setup. The two can be configured side by side with no problem - just make sure your router has enough throughput to handle it all.
Here is a link to setting up site to site on a 2600 router - this should get you up and running! Go to the bottom of the article and download the "template" - this will automatically generate all commands you need to get this working. You do need an account to get this but the signup is free.
http://articles.techrepublic.com.com/5100-10878_11-6130365.html 
Cheers! Let me know if you have any questions!
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 2

Author Comment

by:Italia_NYC
ID: 22672083
I guess the help I am seeking or where the confusion stems from, is I'm pretty sure you can only apply one crypto map per interface. So I have one applied now for Remote Access and am perhaps unsure how to modify the existing crypto map to accommodate both. Excellent link you provided though Puggle! Thanks!
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22672179
You use the same crypto map. Do you have a contract on the device? If you do, just contact Cisco and they'll guide you through it. Otherwise, post your config and I'll take a look.
Cheers!
0
 
LVL 2

Author Comment

by:Italia_NYC
ID: 22672643
No Cisco contract unfortunately. The config is posted above in my original post; did you need something else that will help? Thank you for the assistance.
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22679919
Did you try the template I sent you? That will give you the commands you need.
Like I said - remote access and S2S work just fine side by side. Just try it out.
Cheers!
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question