Solved

Remote access VPN and site-to-site VPN connections on one router

Posted on 2008-10-07
7
312 Views
Last Modified: 2012-05-05
Currently have a Cisco 2610 router configured for remote VPN access via the Cisco VPN Client. We would like to also use this same router in a site-to-site VPN scenario to another office. Is it possible to provide both these services with this one router and one public IP address? I thought you could only apply one crypto map to the outside interface?

Below is our current running-config; Thanks for any help.


version 12.3
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname VPNrouter
!
boot-start-marker
boot system tftp c2600-ik9o3s3-mz.123-18.bin 10.200.202.50
boot-end-marker
!
enable secret 5 $1$/uXD$.pXv9eM.XBJYm9cBbiUjd1
!
aaa new-model
!
!
aaa authentication login local local
aaa authorization network VPN local
aaa session-id common
ip subnet-zero
ip cef
!
!
no ip domain lookup
!
ip dhcp pool test
!
ip audit po max-events 100
!
!
!
!
!
!
!
!
username **** password 0 ****
username **** password 0 ****
username **** password 0 ****
username **** password 0 ****
!
!
!
crypto isakmp policy 3
 encr 3des
 authentication pre-share
 group 2
!
crypto isakmp client configuration group ****
 key creatine
 dns 10.200.202.50
 domain xxxx.com
 pool VPNpool
 acl 101
!
!
crypto ipsec transform-set VPN esp-3des esp-md5-hmac
!
crypto dynamic-map dynmap 10
 set transform-set VPN
!
!
crypto map VPNmap client authentication list local
crypto map VPNmap isakmp authorization list VPN
crypto map VPNmap client configuration address respond
crypto map VPNmap 10 ipsec-isakmp dynamic dynmap
!
!
!

interface Ethernet0/0
  ip address 10.200.201.100 255.255.255.0
 ip broadcast-address 0.0.0.0
 half-duplex
 crypto map VPNmap
!
!
ip local pool VPNpool 10.200.203.1 10.200.203.50
ip http server
no ip http secure-server
ip http path flash:
ip classless
ip route 0.0.0.0 0.0.0.0 10.200.201.254
!
access-list 101 permit ip 172.16.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 192.168.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 172.30.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 10.200.0.0 0.0.255.255 10.200.203.0 0.0.0.255
access-list 101 permit ip 10.100.0.0 0.0.255.255 10.200.203.0 0.0.0.255
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 exec-timeout 90 0
 password ****
!
!
end
0
Comment
Question by:Italia_NYC
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 22663757
I do this on a Netscreen 5 GT, so I would think that it should work on a Cisco, but it may be device dependent.

0
 
LVL 2

Author Comment

by:Italia_NYC
ID: 22663907
I applaud your effort and participation SysExpert. Unfortunately however, that was not very useful to me.
0
 
LVL 12

Accepted Solution

by:
Pugglewuggle earned 250 total points
ID: 22666114
Yes, you absolutely can setup both site-to-site VPN and remote access VPN on a Cisco router. I do it all the time.
What exactly do you need help with? I see that you've already got remote access setup. The two can be configured side by side with no problem - just make sure your router has enough throughput to handle it all.
Here is a link to setting up site to site on a 2600 router - this should get you up and running! Go to the bottom of the article and download the "template" - this will automatically generate all commands you need to get this working. You do need an account to get this but the signup is free.
http://articles.techrepublic.com.com/5100-10878_11-6130365.html 
Cheers! Let me know if you have any questions!
0
Don't Miss ATEN at InfoComm 2017!

Visit booth #2167 to see the  new ATEN VM3200 32 x 32 Modular Matrix Switch. Other highlights include the VE8950 4K HDMI Over IP Extender, VS1912 12-Port DP Video Wall Media Player  and VK2100 ATEN Control System. Register now with Free Pass Code ATEN288!

 
LVL 2

Author Comment

by:Italia_NYC
ID: 22672083
I guess the help I am seeking or where the confusion stems from, is I'm pretty sure you can only apply one crypto map per interface. So I have one applied now for Remote Access and am perhaps unsure how to modify the existing crypto map to accommodate both. Excellent link you provided though Puggle! Thanks!
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22672179
You use the same crypto map. Do you have a contract on the device? If you do, just contact Cisco and they'll guide you through it. Otherwise, post your config and I'll take a look.
Cheers!
0
 
LVL 2

Author Comment

by:Italia_NYC
ID: 22672643
No Cisco contract unfortunately. The config is posted above in my original post; did you need something else that will help? Thank you for the assistance.
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22679919
Did you try the template I sent you? That will give you the commands you need.
Like I said - remote access and S2S work just fine side by side. Just try it out.
Cheers!
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA 5505 packet drops 14 70
TZ400 2 41
Cisco ASA 5510 Question 2 29
Problem to VirtualBox Internet connection 1 52
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question