Can I use a Cisco 2821 as a VPN Concentrator

I have a 10 Mb Fibre connection coming into a 2821 ISR that is doing NAT, etc... I have had issues in the past getting site to site VPN's working on it... The company recently purchased another 2821 with the SSLVPN module in it. I am wondering if I can set this router up strictly for VPN and remote access to offload VPN from the primary router. I want to hang the concentrator 2821off the main 2821 and I want to give the VPN Router one of my public IP's and route all VPN traffic from the main router to the VPN router.
I think this will work but I'm having a problem figuring out what the configuration would look like. If anyone can help me out, maybe point me in the right direction, it would be greatly appreciated.
Thanks in advance.

...IPS are subbed...
i will configure the outside interface with a public ip x.x.x.x the inside will have a 192.169.1.1 IP with a secondary IP of 172.20.1.1 There will a nat entry that says public ip vpn.vpn.vpn.vpn goes to 172.20.1.2 which will be the outside interface of the vpn router. the inside interface IP is where i am havin issues deciding how it will be able to access the regular LAN. Am I not getting it? Sorry still a little green with Cisco.

Similar Messages

  • Can I use the Cisco license transfer tool to rehost licenses from router 2900 to new router 2900? is not rma process

    Can I use the Cisco license transfer tool to rehost licenses from router 2900 to new router 2900? is not rma process
    thank you

    Yes you can. 
    Alternatively, you can email [email protected]

  • Can i use a cisco RE1000 range extender with airport extreme

    Can I use a Cisco R1000 range extender with airport extreme?

    Apple's "extend a wireless network" function appears to be a proprietary feature that will only work with other Apple routers.
    As far as we know, devices from other manufacturers are not compatible with this feature.
    Bottom line....It would be extremely unlikely that this would work, but it's worth a try if you already have the products in hand.
    Please post on your results.

  • Can I use ISE IPN without posture for VPN with Base license only?

    I'm looking at ISE licensing, and both Base and Advanced licenses have VPN listed. I could not find any document that provides guideline for VPN implementation using ISE Base license only.
    1. Can I use ISE IPN (Inline Posture Node) functionality without posture assessment with ISE Base license only? (I know it has to be ISE hardware appliance, and I know that Posture assessment requires ISE Advanced license.)
    2. Do I have to use IPN for VPN deployment using ISE as the Radius server?
    3. If I do not have to use IPN for VPN, can I use ISE for Authentication and Authorization in the same way as I use ACS?
    Thanks,
    Val Rodionov

    Val,
    There is no need to consider IPN if you are not using posturing. You can use ISE much like ACS for radius authentication for vpn users.
    If posturing is down the road and your hope is to have an architecture in place and license later, then I am sure that you can use the ipn with base licensing, however I would strongle recommend working with the PDI (for partners) for help and confirmation.
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • Can i use 2 AirPort Extreme in a VPN?

    i will know if is it possible to do à VPN with to distant airport extrem?

    There is no VPN client or server in the apple routers. Not now, not in the past and it is unlikely they will add one in the future. You can VPN through the apple router.. it is as all routers, a vpn passthrough device. But don't be surprised if you have issues with IPSEC as it has some usage made of the ports by BTMM.

  • Can you use a 3600 for an Ethernet bridge??

    Can you use a Cisco 3600 to do a P2P bridge? Using the MAP's ethernet port  to connect to a remote LAN?  On that remote LAN can you have  lightweight APs that connect to a controller on the RAP side?

    Can you use a 3600 for an Ethernet bridge??
    http://www.cisco.com/en/US/docs/wireless/controller/7.0MR1/configuration/guide/cg_mesh.pdf
    Check - Converting Indoor Access Points to Mesh Access Points
    Ethernet bridging has to be enabled for the following two scenarios:
    1. When you want to use the mesh nodes as bridges.
    2. When you want to connect Ethernet devices such as a video camera on the MAP using its Ethernet port.
    Wireless Backhaul:
    In a Cisco wireless backhaul network, traffic can be bridged between MAPs and RAPs. This traffic can
    be from wired devices that are being bridged by the wireless mesh or CAPWAP traffic from the mesh
    access points.
    Guidelines For Using Voice on the Mesh Network
    • Voice is supported only on indoor mesh networks in release 5.2, 6.0, 7.0, and 7.0.116.0. For
    outdoors, voice is supported on a best-effort basis on a mesh infrastructure.
    other factors to note:-
    #you would be running on backhaul using A radio which is prone to DFS.
    #CAPWAP may not tolerent enough with AWPP convergence on MAP roaming.
    #CAPWAP is more latency sensitive than voice.

  • IPT over IPSEC lines with cisco 2821

    We are implementing a IPSEC VPN Connection over leased lines using cisco 2821 without AIM-VPN Hardware accelerators.
    The line is 2 Mbps and should carry also IPtelephony traffic (4-5 conversations). Will we have problems by mastering the jitter? Since the traffic is devided in small packet, il the 2821 able to handle it accordignly?
    Thanks and bye Giorgio

    Giorgio,
    You should be fine with this configuration. Running voice and video over VPN is certainly a viable solution. It is commonly known as V3PN. Take a look at the V3PN SRND below for best practices, planning, and design tips. As mentioned in this document, IPSEC adds a trivial amount of delay (2 - 5 msec.) to voice deployments.
    V3PN SRND
    http://www.cisco.com/application/pdf/en/us/guest/netsol/ns241/c649/ccmigration_09186a00801ea79c.pdf
    Hope this helps. If so, please rate the post.
    Brandon

  • How many Voice connections can cisco 2821 support?

    Good day.
    I have a cisco 2821 with EVM slot, NME-X slot and two HWIC slots. I have 4 port FXOs on the two HWIC slots. The EM-HDA-8FXS module on the EVM slot can handle 8 FXS connections. Please i would like to know if there is an EVM module that can do FXO connections and also how many voice connections can this router handle in total. Can the EM-HDA-8FXS module handle both FXS and FXO connections?
    Hope someone can help me out. My deadline has already passed.
    Regards,
    Obinna.

    Hi, already replied to this in the appropriate forum.
    Please do not open duplicate threads.

  • Can I use an airport express to extend a Cisco E4200 802.11n or 802.11g wireless network?

    Can I use an Airport Express to extend a Cisco E4200 802.11n or 802.11g wireless network?  I'd like to improve access in a dead spot with an airport express. I know I can connect this wayt for airplay, but how about extending the signal?
    Thx! ACB

    Apple's "extend a wireless network" function appears to be a proprietary feature that works only with other Apple AirPort routers. As far as we know, this feature is not compatible with devices from other manufacturers.
    It would be extremely unlikely that the Express could do what you want, but some things are never known until  you try.

  • Can i use cisco 2951 cme 9 router to connect different branch location ip phones together with different subnet?

    hi all,
    I want to do VoIP , with cisco 2951 router with cme 9.0. I just want to know can i connect differnt branch  ip phone in differnt subnet in single centralized cme router 2951.
    that is for differnt branch ip phone there is differnt dhcp pool and then interVlan routing or as such.
    i have already done it for 1 location ,can i uses that single router to connect there all branch office?
    thank you
    regards,
    vishakha

    Yes that works. The phones get an IP from the local site with the info where to reach the TFTP-Server (which is typically the CME). From there the phones load a config file and learn the IP of the CME. The rest is pure routing from the phone to the CME.
    I don't know where marin and thana is, just make sure that the delay and jitter between the sites is inside an accepted range of < 150ms (latency) and < 30 ms (jitter).
    Don't stop after you've improved your network! Improve the world by lending money to the working poor:
    http://www.kiva.org/invitedby/karsteni

  • You can configure Speed Dial using your Cisco IP Phone

    You can configure Speed Dial using your Cisco IP Phone
    Please check the video: http://youtu.be/ue7gyRj8n9w
    For more information please mail to [email protected]

    I think that eventually these darn things just break - at least that's my experience. Does anyone know of a cool quick fix for a stand that won't stand.  
    Thanks!
    This topic first appeared in the Spiceworks Community

  • Can I use Sandisk Compact 4GB Flash card on Cisco 2800 series Routers

                       Can I use Sandisk Compact 4GB Flash card on Cisco 2800 series Routers

    Yes can confirm the Sandisk Compact 4GB Flash Card works in 2800 series, the exact card above...
    Initially I attempted to shrink the partition on the card to a 2GB FAT partition using the steps here http://timescience.wordpress.com/2010/08/09/how-to-downsize-a-4gb-compact-flash-card-to-2gb/
    However when I inserted it into the router and tried a directory list it wouldn't have a bar of it...
    *Jun 23 14:11:01.391: %FILESYS-5-CF: CompactFlash insertedrtrvoip#dir flash:%Error opening flash:/ (Invalid DOS media or no media in slot)rtrvoip#format flash:
    So I ended up running a format flash and voila, 4GB of flash memory no problems...
    rtrvoip#format flash:Format operation may take a while. Continue? [confirm]Format operation will destroy all data in "flash:".  Continue? [confirm]Writing Monlib sectors....Monlib write completeFormat: All system sectors written. OK...Format: Total sectors in formatted partition: 7812945Format: Total bytes in formatted partition: 4000227840Format: Operation completed successfully.Format of flash: completertrvoip#dir flash:Directory of flash:/No files in directory3999793152 bytes total (3999793152 bytes free)

  • Cisco 3750X -- 10G uplink - Can be used as access port?

    Dear All,
    I have small question, I am planning for Cisco 3750X with 10G SFP+ service module. I want to know that whether it can be used as Access Ports connecting to server as this is mostly used as uplink port.
    Thank You,
    Abhisar.

    Disclaimer
    The  Author of this posting offers the information contained within this  posting without consideration and with the reader's understanding that  there's no implied or expressed suitability or fitness for any purpose.  Information provided is for informational purposes only and should not  be construed as rendering professional advice of any kind. Usage of this  posting's information is solely at reader's own risk.
    Liability Disclaimer
    In  no event shall Author be liable for any damages whatsoever (including,  without limitation, damages for loss of use, data or profit) arising out  of the use or inability to use the posting's information even if Author  has been advised of the possibility of such damage.
    Posting
    Well if you want to connect anything with 10g to a 3750X, you're limited to using a module with 10g ports. 
    Other than 10g capability on some module cards, something to note, the module ports, I believe, are supported by larger buffers (including the gig module ports).
    As the others have noted, you can use any port for any purpose.  However, if you connect a server to a 10g port, be aware you might start to see drops on your other host (gig) ports as the server will now be able send faster than the host port can receive data.  To minimize this, you might either disable QoS on the switch (providing maximum buffers to all egress traffic) or you might need to tweak buffer resource settings (the default settings often drop some packets, when there are bursts, of default marked packets).

  • Can I use Cisco Connect if I change the default router IP address?

    I am adding my E3000 into an existing network behind a SonicWall firewall.  I am using an address scheme of 192.168.168.xxx  When I change the router address to 192.168.168.10 and disable DHCP in Cisco Connect, I am left with only being able to access the router through the web interface.  This seems pretty lame; I've read other threads on Web vs. Cisco Connect.  Is there a quick fix that will allow Cisco Connect to still find the router after I've made (just) these two changes?
    --David C

    Yes you still will be able to use the Cisco Connect software if you have changed the Routers IP address, But if you change the Router password of Wireless Security then you wont be able to use Cisco Connect software.

  • Valcom 2001A single zone paging system with a Cisco 2821 FXS port

    I am new at troubleshooting the Valcom paging system with Cisco 2821 router.  I recently installed a Valcom 2001A that is connecting to FXS port on the Cisco router.  The paging works but the ringing does not stop when the page extension is dialed (you can talk over the ringing).  I was told to use the Valcom 9970 to work with the FXS port on my router.  Will the V9970 worth with the 2001A or in place of it?  Is there anything else I need to know to perfect this install?  Thank you! 

    Put the command 'forward-digits extra ,,,,01' on the outgoing POTS dial-peer. Each comma is one second of delay.

Maybe you are looking for

  • Windows 8.1 and icloud doesnt sync photos

    Just installed icloud to my windows 8.1 laptop and it doesnt sync photos at all with my air2 (8.1.2). I have tried to sign in, out, middle, top, bottom, front, behind or whatever... Changed compatibility to Win7 etc. Turned off/on icloud sync/photos/

  • Recovery onto hard drive from another system - Pavilion 790n

    This old computer was scrapped and hard drive is being used in another system.  I've decided to let the kids use it and have it up and running again, but used a hard disk from an old emachine computer - I thought I'd wiped it clean, but didn't remove

  • How to change the response of human task if we are using the skip rule

    Hi, We have developed the request workflow in OIM11g for this we are using the Beneficiary Manager approval composite to approve the request by his manager. We are using the skip rule in the human task component to skip the user if the requester is b

  • XI and R/3 Installation on One System

    Hi,   I am new To XI and I want to install XI and R/3 in My Local System. Can i install both in one system (OS)? If yes, what is the minimum requirement for this?   If any one have did this, please help me. Thanks, Sridhar

  • JSP development and security issue

    I saw several "serious integrations" and also some postings here which are suggesting to put a jsp in /public_html directory... Be aware, that nothing will prevent a user from uploading a new jsp to this location and then executing it from a remotely