Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

VPN on cisco ASA 5510 with multiple remote sites with same IP segment.

Posted on 2009-07-12
8
Medium Priority
?
527 Views
Last Modified: 2012-05-07
We are going to have 10 remote sites connect to us for a L2L VPN to access data at our location. We have no control over the remote sites, and my guess is most will br 192.168.1.x IP range. How can we make this work?? Remember, I have no control over the remote sites, so any natting will have to be done on my side.
0
Comment
Question by:advizex_tech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
8 Comments
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 24835644
HI,

It is a problem! In my opinion you not eble to do this via L2L, better way to use VPN server and remote sites computer connect with wpn client!

Best Regards,
Istvan
0
 

Author Comment

by:advizex_tech
ID: 24835779
That's not an option we can use.
0
 
LVL 7

Accepted Solution

by:
clonga13 earned 2000 total points
ID: 24863664
You would need to configure NATing for overlapping networks. You would NAT their traffic to a specific IP or subnet on your end. Their networks wouldn't matter. Here is an example:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9950.shtml
0
Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 24863736
Hi,

If you want to make an IPSEC tunnel you must add source and destinaton address, how can you say it to the router if the source and the destination address are same?
0
 
LVL 7

Assisted Solution

by:clonga13
clonga13 earned 2000 total points
ID: 24863831
Because you would be NATing the addresses on your end. For example, if all of your sites use 192.168.1.0 as their subnet, you would NAT site A to 10.1.0.0, site B to 10.2.0.0, site C to 10.3.0.0 and use these new subnets to write the access lists for your crypto maps.
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 26163717
HI, Qlemo

Nobody added the that the asker want, so In this case In my opinion I would like to split with clonga13 the points....
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question