Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco VPN300 to 3002HW Client Routing

Status
Not open for further replies.
Dec 11, 2003
17
0
0
US
I have a Cisco 3000 Wardware VPN client setup at a remote office connected to my 3000 VPN concentrator at the home office. The tunnel is up and I can ping from 3002 into my network here in the home office. I can also ping from the home office to the internal interface of and devices of the remote office on the 3002 HW client. What I cannot do is ping the other subnets on the remote site. What roues would I need to do this:
Ping from Home office 172.16.1.xxx to all remote office subnets via VPN tunnel?
Addressing:
Home Office: 172.16.1.xxx
VPN3000 Inside: 172.16.1.77
VPN 3000 Outside: (Internet Address)
VPN 3002 Outside: (internet Address)
VPN 3002 Inside: 10.23.1.82
Remote Office: 10.23.1.xxx & 10.23.2.xxx

I CAN ping the 10.23.1.xxx address from the home office. I CANNOT ping the 10.23.2.xxx address from the home office, but I CAN from the 3002 HW client.
the trouble seems to stem from the home office VPN 3000 not knowing how to route to the remote sites other subnet.
Thank you
 
Correction above:
Home office has Cisco 3000 VPN Concentrator
Remote Office has Cisco 3002 VPN Hardware Client

Also verified I can ping/trace from remote office VPN client to other subnets on home office site, but not from home office to other subnets on remote site.
 
It looks like the pings to the other subnet in the remote site (3002 Client side) are being routed to the Internet on the home office side. Now I've tried configuring static routes pointing to every interface on the 3000 concentrator as-well-as the interfaces on the remote site's 3002 just for giggles, but I can't force traffic destined to the remote network's other subnet to go through the tunnel. What the heck am I missing??
Does the remote side's other subnet need to create traffic to the home office for the 3000 concentrator to learn the route back?
Hello? Anyone out there?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top