Overlapping private subnets on b2b tunnel

Posted on 2009-07-09
Last Modified: 2012-05-07
How do we define interesting traffic on an b2b tunnel with overlapping private subnets.Please see the jpg file attached.
Question by:harish_a4u
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 78

Accepted Solution

arnold earned 250 total points
ID: 24823547
What router do you have? Is altering the segment on one side out of the question?

You have to mask the LAN IPs for the purpose of the VPN.
Side A for the purpose of outgoing traffic need to pretend as though it is a different IP segment and the same for site B.

have a look at the link below where it discusses on to setup a site-to-site VPN between sites that have overlaping segments.
LVL 79

Assisted Solution

lrmoore earned 250 total points
ID: 24823666
Nat the traffic first, then the interesting traffic is defined by the natted IP addresses. NAT has to happen on both sides.
I2 nats to
Lenovo nats to

I2 defines interesting traffic:
 access-list 101 permit ip

Lenovo is mirror image
 access-list 101 permit ip


Author Comment

ID: 24845858
Thanks Irmoore and arnold.I will try this in my lab.

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SSIS with VPN COnnection 2 144
Setting up L2TP/IPsec in RRAS 5 78
SSL-VPN Solution 8 36
DNS and Promoting Server 2012R2 to DC Issues 10 48
One of the Top 10  common Cisco VPN problems are not-matching shared keys. This is an easy one to fix, but not always easy to notice, see the case below. A simple IPsec tunnel between fast Ethernet interfaces of routers SW1 (f1/1) and R1(f0/0). …
Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question