Cisco 5505 ASA Site to Site VPN question

Hi All...

I am preparing to configure a Site to Site VPN from our head office to a new remote location in the very near future. I am fretting about how our network is configured and if I'll run into problems.

Our Network it set up more or less as follows:

<--10.0.0.0/24 (LAN) (Linksys RVS4000 set to "Gateway") ---192.168.1.3(WAN)---> <---192.168.1.1(Cisco ASA 5505) ---Outside IP--->

When I set up the VPN, I need our remote location to be able to access the 10.0.0.0/24 network. Do I need to do any fancy configurations to get the Tunnel to cross the 192.168 network?
LVL 1
TORLYSITAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

TORLYSITAuthor Commented:
Adding a simplistic vis. drawing of the network I'm speaking ofNetwork diagram
Schuyler DorseyCommented:
I'm sort of confused here...

Are are Linksys gateway and Cisco ASA separated across the internet? (I assume so by your saying a new remote site). But your diagram is confusing to me.

Just curious.. why do you have a Cisco RVS at 192.168.1.3 then going to the ASA at 192.168.1.1? I'm not quite sure what your WAN segment is accomplishing year. I often see a l3 switch or a router with a /30 between itself and the firewall for security reasons but unsure on your setup.

But.. a standard site to site vpn shouldn't be an issue regardless.
TORLYSITAuthor Commented:
The ASA and the RVS4000 are at the same site (This was built before I was hired to admin it.)

Instead of creating a Port based DMZ, one of my predecessors installed an RVS4000 in Gateway mode with IP ACLs limiting traffic from the 192.168.1.0/24 network to the 10.0.0.0/24 network (All local traffic) sitting behind a Cisco ASA 5505 that terminates at our ISP Router.

I'm currently working on an initiative to find out if I can untangle it without impact but have to set up the new site in a short bit. Hence my question about site to site in our current environment.
Defend Against the Q2 Top Security Threats

Were you aware that overall malware worldwide was down a surprising 42% from Q1'18? Every quarter, the WatchGuard Threat Lab releases an Internet Security Report that analyzes the top threat trends impacting companies worldwide. Learn more by viewing our on-demand webinar today!

Schuyler DorseyCommented:
There shouldn't be an issue setting up the site to site even in the current setup.
Alan Huseyin KayahanCommented:
RVS4000 in Gateway mode with IP ACLs limiting traffic from the 192.168.1.0/24 network to the 10.0.0.0/24 network

Make sure you put an permit ACE in RVS400 allowing traffic sourced from the local network of Beli networks destined to 10.0.0.0/24.

Second, make sure that RVS4000 is not doing any type of NAT between 10.0.0.0/24 and 192.168.1.0/24

Finally make sure that the local side of the interesting traffic ACL in ASA is 10.0.0.0/24 and not 192.168.1.0/24

Doublecheck if RSV4000 has either a default route or manual route regarding Beli Networks' local subnet to 192.168.1.1. Also ASA has a route to 192.168.1.3 for 10.0.0.0/24

As an advice, in case you need to go for restructuring your network, never use the factory default subnets of many vendors such as 192.168.1.0 or 10.0.0.0. It would cause you headaches if by any chance the remote end of the VPN is using the same subnet.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
TORLYSITAuthor Commented:
Thank you MrHusky.

The subnets were definitely not my choice as I inherited the whole thing when I started here.

Thanks for all the information!
Alan Huseyin KayahanCommented:
You are welcome!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.