Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Setting up a second 2821 as a VPN Concentrator 2

Status
Not open for further replies.
Sep 16, 2009
11
0
0
US
I have a 10 Mb Fibre connection coming into a 2821 ISR that is doing NAT, etc... I have had issues in the past getting site to site VPN's working on it... The company recently purchased another 2821 with the SSLVPN module in it. I am wondering if I can set this router up strictly for VPN and remote access to offload VPN from the primary router. I want to give the VPN Router one of my public IP's and route all VPN traffic from the main router to the VPN router.

I think this will work but I'm having a problem figuring out what the configuration would look like. If anyone can help me out, maybe point me in the right direction, it would be greatly appreciated.

Thanks in advance.
 
absolutely you can do this. as a matter of fact this is very common configuration. i'm assuming that you use either a firewall or a l3 switch as your gateway for your internal networks?? if so you'll need to set the proper routes in that device.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
I am trying to figure out how the confiugrations will look as far as the IP's go on the segment after the 2821 for the VPN does its authentication and encrypting. Would that 2821 need to have an ip that is on the network already? Would I need to add a secondary IP on the main router on the subnet as the VPN router...Excuse my ignorance I'm fairly green to Cisco VPN.

The main router has been doing the firewall and access-lists.
 
Take a look at this drawing. Hopefully it gives you an idea on how this would look.


I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
sure. i'm at shonuff6699[aA][tT]yawhoo dot comm


I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top