Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Two IPsec tunnels and hairpin between them

Status
Not open for further replies.

cormon

Technical User
Mar 4, 2005
73
0
0
GB
HI Guys,

I have the following requirement to achieve and just need to ensure that it is possible. Please see attached the relevant diagram.


The Firewall in the Middle (Data Center) has only one purpose to terminate the VPNs and hair pin them . It has no LAN.

Why are we doing this ?? Company 2 needs to see the source of the ipsec traffic to be an Indian ip addr.

I need to have the traffic flow between the 10.21.121.0/24 on site 1 to the network 192.168.7.0/24 on site B .Is this possible once I have.

same-security-traffic permit intra-interface

the networks at both ends included in the encryption domain.
a no nat statement on the middle firewall for the both networks,

How would I place a second firewall in the middle tier to be redundant if the main one failed. HSRP or similiar ???

Thanks in advance
 
Why not just establish a second ipsec connection between the two sites? It doesn't make much sense to go through the additional overhead of traversing two tunnels to get to it's destination when it could be done with one.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top