Cisco 3030 VPN+WAN to WAN config....

Rogue

Banned
Jan 28, 2000
5,774
0
0
I've been charged with setting up a new Cisco 3030 VPN Appliance to connect from Illinois to Kansas. Desired topology is as follows:

1) Established Cisco 3030 VPN in Kansas already, IP address 1.2.3.4
2) New Cisco 3030 VPN going to Illinois, IP address 9.8.7.6
3) 24 clients behind Illinois VPN on switch need to remote connect over tunnel to Kansas and log in to Win2k domain.

So far I have been able to setup a Lan-to-Lan IPSec link and have the two remote ends see eachother, however, I can't get any client PCs to attach to the Illinois VPN and talk to the Kansas network. It's not switch related, all the PCs can talk to eachother on the LAN, just cannot talk over VPN tunnel to KS. Any experience with this? Suggestions? Configuration tips? All help appreciated. If more info if needed, let me know.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
ok.

lets work our way up the stack.

can client computers ping from one lan to the other?

As far as the tunnel is concerned if the tunnel is up (as you can see in the logs of the 3030) then you should be able to ping from one end to the other. If that is good we can move on...if hosts on one lan cannot ping others on the other lan then we need to investigate IP addresses/masks/gatewas as well as the tunnell setup.
 

Boscoh

Senior member
Jan 23, 2002
501
0
0
You got SmartNet right? Go sign up for a CCO account (you'll need your SmartNet contract number) and you'll get access to a ton of configuration examples for the VPN concentrators.

However, as Spidey already said, it is probably something with the ip/subnet/gateway or the tunnel/acl config.