Solved

Cisco ASA Tunnel

Posted on 2010-08-20
11
347 Views
Last Modified: 2012-06-21
Is it possible to use a Cisco ASA 5505 for the following:


172.18.112.0/18(inside)----> 10.1.1.1(outside)-->internet--->10.1.1.2(outside)---->172.18.112.0/18(inside)


We want to extend our current network to a new building for a seasonal warehouse, but I am wondering if I can have that same network over there or if I need a new network over there completely.

thanks!
0
Comment
Question by:dbs0026
  • 3
  • 3
  • 3
  • +1
11 Comments
 
LVL 34

Expert Comment

by:Istvan Kalmar
Comment Utility
No, it is impossible!

I advise to use individual subnets, or use on SITE A the first /19 address and use the second /19 address on  SITE B
0
 

Author Comment

by:dbs0026
Comment Utility
So you can't even setup a site to site vpn and use it in Transparent mode?
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
Comment Utility
No, you not able to use same subnet for local and remota address... If you want it I advise to use L2tpV3
0
 
LVL 17

Accepted Solution

by:
Kvistofta earned 500 total points
Comment Utility
"impossible" Oh no!

You need to do  policyNAT of the traffic entering the vpn tunnel.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9950.shtml

/Kvistofta
0
 
LVL 17

Expert Comment

by:Kvistofta
Comment Utility
Of course, it is not the same network. You cannot do "bridging", but you can connect two networks with the same addressins by doing address translation.

/Kvistofta
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 

Author Comment

by:dbs0026
Comment Utility
So by doing address translation, I can have 172.18.112.0/20 on both my LAN here in the office and on our LAN in the remote warehouse?

There will be a DSL connection for the "outside" interface to set the vpn tunnel up with.
0
 
LVL 17

Expert Comment

by:Kvistofta
Comment Utility
Yes, but you need to "fool" the hosts on each side that the other sides ip adddresses are something else.
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
Comment Utility
Do you have routers? Or only ASAs?
 how many the bandwith?
0
 

Author Comment

by:dbs0026
Comment Utility
We only have asa's for this project, I am sure I could come up with some older 2600's though. If I need to put a different subnet on the remote end, I can. My goal was to keep it though the same and just have the Vpn tunnel in between. The traffic going between is minimal, symbol rf scanning guns for product shipping.
0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Suggested Solutions

Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now