Avatar of bfpnaeechange
bfpnaeechange
 asked on

VPN hub and spoke question

I need two branch routers to be able to pass traffic to each other without a dedicated vpn tunnel between the two branches.


HQ LAN is 172.16.x.x and 172.17.x.x

Branch Routers use 192.168.x.x


***PIX***



access-list nonat permit ip 172.16.0.0 255.255.0.0 192.168.48.0 255.255.255.0
access-list nonat permit ip 172.17.0.0 255.255.0.0 192.168.48.0 255.255.255.0

access-list mtl01rt01ec permit ip 172.16.0.0 255.255.0.0 192.168.48.0 255.255.255.0
access-list mtl01rt01ec permit ip 172.17.0.0 255.255.0.0 192.168.48.0 255.255.255.0

route outside 192.168.48.0 255.255.255.0 "Internet Router"


**************************************************************************

***Spoke router 1***



crypto map nolan 18 ipsec-isakmp
 set peer "HUB PIX"
 set transform-set sharks
 match address 121


access-list 110 deny   ip 192.168.48.0 0.0.0.255 172.16.0.0 0.0.255.255
access-list 110 deny   ip 192.168.48.0 0.0.0.255 172.17.0.0 0.0.255.255
access-list 110 permit ip 192.168.48.0 0.0.0.255 any
access-list 121 permit ip 192.168.48.0 0.0.0.255 172.16.0.0 0.0.255.255
access-list 121 permit ip 192.168.48.0 0.0.0.255 172.17.0.0 0.0.255.255
!
route-map nonat permit 10
 match ip address 110


ip nat inside source route-map nonat interface Ethernet0 overload
**************************************************************************

***Spoke router 2***


crypto map nolan 18 ipsec-isakmp
 set peer "HUB PIX"
 set transform-set sharks
 match address 121


access-list 110 deny   ip 192.168.49.0 0.0.0.255 172.16.0.0 0.0.255.255
access-list 110 deny   ip 192.168.49.0 0.0.0.255 172.17.0.0 0.0.255.255
access-list 110 permit ip 192.168.49.0 0.0.0.255 any
access-list 121 permit ip 192.168.49.0 0.0.0.255 172.16.0.0 0.0.255.255
access-list 121 permit ip 192.168.49.0 0.0.0.255 172.17.0.0 0.0.255.255
!
route-map nonat permit 10
 match ip address 110


ip nat inside source route-map nonat interface Ethernet0 overload
VPNNetwork SecurityNetworking Hardware-Other

Avatar of undefined
Last Comment
John Meggers

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
John Meggers

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck