Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Routing to a DMZ in a spoke from a different spoke in hub and spoke VPN config

Posted on 2012-03-13
1
Medium Priority
?
615 Views
Last Modified: 2012-04-19
As a company, we use a hub and spoke configuration.

The hub is a Cisco ASA 5510. Spokes are Sonicwall TZ100.

I'm sitting behind one of the spokes @ 10.40.45.1/24. On another spoke @ 10.40.46.1, I've put a server in a DMZ. The gateway address of the DMZ in 10.40.200.1.

I'm not sure if this is a routing issue for the Cisco, or a routing issue for the sonicwalls, but I would like to reach the DMZ'd device @ 10.40.200.100 from my computer @ 10.40.45.100. The Cisco is @ 192.168.199.1

Thanks in advance.
0
Comment
Question by:kblackwel
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 57

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 37718775
With a sonic wall on your site   - I'm not sure if it would work? but if you had an ASA it would,

You would need to add the distant DMZ Subnet mask to the cryptomap ACL that goes to the main site. Then you would need to go to the main site and add the DMZ subnet to  the other the cryptomap that handles the VPN to your site AND you would need to exempt that traffic from NAT (the command differ depending on the OS you are using)

Pete
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Considering cloud tradeoffs and determining the right mix for your organization.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question