Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco VPN 3000 Routing table issue

Status
Not open for further replies.

hectormz

MIS
Jun 26, 2003
27
US
Hi all,

I have the following routing table in the VPN 3000:

192.168.1.0 255.255.255.0 192.168.5.1 1 Static 0 4
192.168.5.0 255.255.255.0 0.0.0.0 1 Local 0 1
192.168.6.0 255.255.255.0 192.168.5.1 1 Static 0 3
192.168.11.0 255.255.255.0 192.168.5.1 1 Static 0 3
192.168.12.0 255.255.255.0 192.168.5.1 1 Static 0 3

I want to change the 192.168.5.0 network next hop to 192.168.5.1, same as the other networks, but in the Ip Routing part of the VPN config i have this:

Default->XXX.XXX.XX.XX
192.168.5.0/255.255.255.0->192.168.5.1
192.168.6.0/255.255.255.0->192.168.5.1
192.168.11.0/255.255.255.0->192.168.5.1
192.168.12.0/255.255.255.0->192.168.5.1
192.168.1.0/255.255.255.0->192.168.5.1

So in here everything seems to be ok. Does anyone know where o how can i change this setting?

Thanks,

-Hector
 
It looks like 192.168.5.0 is the connected network. It's normal for connected networks to show up as "Local"
 
That's right, is there a way to change de "Local" network next hop to an ip address in the same network?
 
The connected network is there. You don't need to route through another hop to get to it, so you don't need to add that info to the routing table. It's directly connected to the interface. There's no problem with your config.

What are you trying to achieve? Are you trying to proxy all traffic that comes onto the 192.168.5.0 network or something?

CCNA, MCSE, Cisco Firewall specialist, VPN specialist, wannabe CCSP ;)
 
Exactly, my VPN users get an address 192.168.5X from the VPN's Address Pool and when they want to surf they can't cause they're not going through my FW. I need to:

a) Change the next hope for the local route
b) Change the Address Pool ip's

I would go with "b", but my manager choose "a"

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top