Solved

VPN on cisco ASA 5510 with multiple remote sites with same IP segment.

Posted on 2009-07-12
8
515 Views
Last Modified: 2012-05-07
We are going to have 10 remote sites connect to us for a L2L VPN to access data at our location. We have no control over the remote sites, and my guess is most will br 192.168.1.x IP range. How can we make this work?? Remember, I have no control over the remote sites, so any natting will have to be done on my side.
0
Comment
Question by:advizex_tech
  • 3
  • 2
8 Comments
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 24835644
HI,

It is a problem! In my opinion you not eble to do this via L2L, better way to use VPN server and remote sites computer connect with wpn client!

Best Regards,
Istvan
0
 

Author Comment

by:advizex_tech
ID: 24835779
That's not an option we can use.
0
 
LVL 7

Accepted Solution

by:
clonga13 earned 500 total points
ID: 24863664
You would need to configure NATing for overlapping networks. You would NAT their traffic to a specific IP or subnet on your end. Their networks wouldn't matter. Here is an example:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9950.shtml
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 24863736
Hi,

If you want to make an IPSEC tunnel you must add source and destinaton address, how can you say it to the router if the source and the destination address are same?
0
 
LVL 7

Assisted Solution

by:clonga13
clonga13 earned 500 total points
ID: 24863831
Because you would be NATing the addresses on your end. For example, if all of your sites use 192.168.1.0 as their subnet, you would NAT site A to 10.1.0.0, site B to 10.2.0.0, site C to 10.3.0.0 and use these new subnets to write the access lists for your crypto maps.
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 26163717
HI, Qlemo

Nobody added the that the asker want, so In this case In my opinion I would like to split with clonga13 the points....
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

I've had to do a bit of research to setup my VPN connection so that Clients can access Windows Server 2008 network shares.  I have a Cisco ASA 5510 firewall.  I found an article which was extremely useful: It had a solution if you use ASDM to config…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now