Solved

Routing to a DMZ in a spoke from a different spoke in hub and spoke VPN config

Posted on 2012-03-13
1
611 Views
Last Modified: 2012-04-19
As a company, we use a hub and spoke configuration.

The hub is a Cisco ASA 5510. Spokes are Sonicwall TZ100.

I'm sitting behind one of the spokes @ 10.40.45.1/24. On another spoke @ 10.40.46.1, I've put a server in a DMZ. The gateway address of the DMZ in 10.40.200.1.

I'm not sure if this is a routing issue for the Cisco, or a routing issue for the sonicwalls, but I would like to reach the DMZ'd device @ 10.40.200.100 from my computer @ 10.40.45.100. The Cisco is @ 192.168.199.1

Thanks in advance.
0
Comment
Question by:kblackwel
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 37718775
With a sonic wall on your site   - I'm not sure if it would work? but if you had an ASA it would,

You would need to add the distant DMZ Subnet mask to the cryptomap ACL that goes to the main site. Then you would need to go to the main site and add the DMZ subnet to  the other the cryptomap that handles the VPN to your site AND you would need to exempt that traffic from NAT (the command differ depending on the OS you are using)

Pete
0

Featured Post

Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
home router to use as repeater  (signal extender) 10 65
SonicWall Max Connection Setting 7 38
SSL VPN to Fortigate 100D 2 18
Layer 3 switch recommendation 15 51
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question