Help needed - tunnel from behind ADSL router

I have a situation in which I require to set-up IPSec tunnel in between two 1841 routers. This is normally two minutes job, in this case however one of the routers sits on a private LAN behind ADSL router (at the moment there is no reasonable way to get around it).
Thus:
1841-1 <-> WAN <-> ADSL Router <-> 1841-2
1841-1
FE0/1 Private LAN 172.16.1.1
FE0/0 Public IP
|
WAN
|
ADSL Router
Public IP
NAT
Private LAN1 192.168.0.1
|
1841-2
FE0/0 LAN1 IP 192.168.0.1
FE0/1 LAN2 IP 172.16.0.1
172.16.1.0-172.16.0.0 require to communicate over the IPSec tunnel.
Could you please advice me on 1) what is the most practical way to set this up with out loosing sanity; and 2) Could you maybe point me to some documentation that deals with this specific scenario?
Thanks.

'1841-2' does not have public IP (it "fakes" to have one).
IPsec tunnel is fully working now.
In the process though I have learned that it depends on what ADSL modem you are using to get this working.
Check out http://kb.juniper.net/KB4715 for example (this is the one I got working).
You can thus give your Cisco router a private IP behind ADSL router and then follow the steps from the knowledge base article above on ADSL modem (if you have same type available).
In addition then, on your Cisco router - you require to add loopback 0 interface and give it public IP of your ADSL router (yes - your adsl router WAN interface and loopback interface on your Cisco router have now the same public IP).
As the last step, on your Cisco router, change tunnel interface: source interface loopback 0 and destination your remote gateway.
I am going to try different modems, many models can actually do this, but the documentation is often unimpressive.
It is possible that there are better ways to do this, if so, please let me know.
If you wish to have more details about the set-up, let me know.
Thanks.

Similar Messages

  • Is it possible to create a VTI tunnel from my 877 router to my ASA

    Hi all
    I woulke like to know is it possible to create a VTI tunnel from my 877 router to my ASA, rather than creating a cryptomap on the router ?
    cheers
    Carl

    Yes you can
    Forgot to add that it possible when configuring ezvpn where the 877 is a remote client and Asa server
    Sent from Cisco Technical Support iPhone App

  • Private vpn tunnel from behind NAT

    Hello all,
    Our provider suddenly refuses to give us public ip addresses. Instead we get a private one and the provider does nat.
    Problem is this site has an IPSEC tunnel towards a public ip address for connectivity to main offices, the tunnel also runs BGP as routing protocol (so dynamic).
    Is there a way to make this work ? I guess the client side needs to be forced into setting up the tunnel always and the tunnel must be kept alive with hello packets or something like that...
    Any link to some good documentation would be appreciated ?
    regards,
    Geert

    Trying to establish a vpn tunnel from a windows vpn client to a watchguard Firebox X700 VPN.
    Thanks.

  • Can't access locally hosted website from behind the router, but can outside

    Hi, I recently had to be moved from ATT DSL to U-verse. At home I host a small non-commercial website with a domain name registered, listening on port 80.  I can access the website if signed in to my employer's VPN at home, but not from any machine in my home network.  This worked for a few days after switching, but then suddenly stopped working. Any idea what's going on and if it can be fixed? Since I can get to it from VPN, I assume folks outside of U-verse can see it.  How about folks with U-verse as their ISP?  The web site is http://www.jtlanguage.com. Thanks. -John 

    I suspect that the U-Verse RG is smart enough to see that the IP address you are attempting to route to is itself, and it is not applying the port forwarding to traffic coming from internal addresses as it is from external traffic arriving (since the traffic is coming from behind the firewall, not outside it).  If this is the case, you could put a hosts file entry on your local machines to identify the internal IP address rather than the external IP address for the web server, so that the computers go directly to the machine behind the firewall.

  • Seeing Airtunes from Behind a Router

    My setup is on a college network, so when my Airport Express is plugged into the switch on the wall, the people in my dorm can access my remote speakers if they are plugged into the switches on their walls. This is a good thing.
    However, my roommate has a wireless router. When he's behind that router he can't see my remote speakers. I assumed this was a port problem, so I looked up what ports Airtunes uses and came up with with port 3689 and port 5353 UDP. I forwarded both 3689 and 5353. I'm not sure if port 3689 is in UDP, but I forwarded both ports in UDP on my roommate's router. However, he still does not see my remote speakers in iTunes.
    Any suggestions? Am I not forwarding the right ports?

    UncleJemima, Welcome to the discussion area!
    Sorry but Airtunes doesn't cross subnets. A router creates a subnet.
    You might be able to make it work if your roommate disables the DHCP server in the router.

  • Help needed with Wireless ADSL2+Modem Router setup

    I have a iMac 1GHz PowerPC G4 running 10.3.9 with all of the latest software updates and have just purchased a Netgear DG834G. I am currently using an USB modem and now need wireless internet access for remote working via an IBM Thinkpad.
    I have tried to follow the Netgear manual but to no avail. Unfortunately, my ISP was unwilling to help with setup as they didn't supply the router! Typical! Anyway they gave me some settings which might as well be in a foreign language ....
    Virtual Path Identifier VPI = 0
    Virtual Channel Indentifier (VCI) parameters = 38
    ISP Domain Name Server (DNS) Addresses apparently will be automatic
    Fixed or Static IP Address is automatic
    Protocol = PPOA - is this correct?
    Encapsulation =VCMUX
    Any advice and screenshots would be greatly appreciated as I am absolutely stuck.
    iMac 15 G4   Mac OS X (10.3.9)   Lacie Triple D2 160GB + 5G 30gb iPod

    Fixed - told myself to RTFM!

  • Workflow help needed, transitioning from iPhoto/iPhoto Library Manager

    HI all, I am using latest Aperture, iPhoto, and 10.6.3 on lan connected macs and need some help setting up a workflow/libraries that represent some sanity amid the tens of thousands of photos that I have. Before getting Aperture3, i was using iPhoto and iPhoto Library Manager to work between an imac and an mbp; i would create a temp library to travel with on the mbp and then when I returned to the office I would merge the updated temp lib with the master lib housed on a huge external drive hanging off the imac. Using iPhoto Library Manager this is a lot of work and very slow indeed.
    So with my new install of Aperture3, I am sure there is a better way, I just have not found a coherent tut that explains what I should be doing under these circumstances. I see that I can import iPhoto libraries, and that I can also use referenced files to get things into Aperture no matter where they are, or I can ??? Really confused on all the options.
    Ideally, I think what we all want is a cloud like repository for all photos where users could check in and check out photos and have all the metadata preserved, but I guess they also want ice water down under, and haven't gotten that yet either.
    Short of the above fairytale, what can I do? I do expect to have another mbp in the field soon, so that will be two machines/users that will need to pull things out of a master repository and check back in updated files as well as add new files to the collective.
    Thoughts? Thx.
    coocoo
    Message was edited by: coocooforcocoapuffs

    1) Import my one massive iPhoto Library into Aperture 3 - but do I use referenced or embedded options? Is there any advantage to leaving everything in iPhoto and just referencing from Aperture? Or do I get everything into Aperture and then just blow away iPhoto?
    I see no reason to leave the files in iPhoto. If you agree you can do one of two things: either move them elsewhere and reference them or manage them in Aperture. Many folks recommend referencing them, but it's a choice only you can make.
    I see no reason to continue with iPhoto.
    2) In Aperture, I can export a set of projects from the main repository into a "traveling library", say when I take the MBP out on assignment,
    Correct: File -> Export Project as New Library
    and then when I return, I just import that library back and the updates I made on the road will get integrated with the whole again? If so, that's worth the price of admission!
    Correct.
    Regards
    TD

  • Help needed - transfer from Mac to Windows PC

    Hello All,
    Need assistance regarding setting up an ipod touch that I recently purchased. The device was purchased from an individual that used a Mac for syncing. I will be using a Windows PC. How do I go get the ipod to recognize the PC now? Also, the person I purchased the device from has a load of good music and movies loaded. Is there any way I can copy these first (onto my hard-drive) before syncing with my PC (I am afraid that I PC would delete everything that is currently stored on the ipod as I may need to reset it). If not possible to copy the files onto my PC first, could I possibly copy on any other Mac?
    Any help would be appreciated.
    Best wishes.

    On the IPT, go to Settings > General > Reset and clear all settings. Have the current version of iTunes on your PC. Plug in. In iTunes, select the IPT and use the Restore function to return the IPT to the factory state.
    person I purchased the device from has a load of good music and movies loaded. Is there any way I can copy these first (onto my hard-drive)
    Handing the 10-foot pole that I wouldn't use to touch this (quite illegal) issue to the next person to post in this thread...although it may be deleted before then.
    Please read the Terms of Use which you agreed to when you signed up to the Forums, in particular this section:
    +Keep within the Law+
    +No material may be submitted that is intended to promote or commit an illegal act.+
    +Do not submit software or descriptions of processes that break or otherwise ‘work around’ digital rights management software or hardware. This includes conversations about ‘ripping’ DVDs or working around FairPlay software used on the iTunes Store.+

  • Help needed upgrading from 4.1 to 6.2 for transfer to new Pre

    I have a Sony Clie PEG-SJ22 that I sync on two computers using Palm Desktop 4.1.0 on each.  The version on the computer in front of me lives in D:\Program Files\Sony Handheld.  I just bought a Palm Pre and learned that in order to sync my data to it, I would have to first upgrade to Palm Desktop 6.2.  I downloaded the 6.2 installation file and ran it.  It recognized that Palm Desktop was already installed and prompted me to click "Yes" to upgrade it which I did.  However the installation froze with the progress bar about 3/4 of the way through.  I End-Tasked the installation, but now I can't run either the new version or the old one.  (In fact the new version seems to have disappeared from \Program Files.)  When I try to run the old version I get error messages about missing dll files.  Before I try re-installing (or anything else) what should I do to make this go properly?  Is there a problem because my old version of Palm Desktop was a Sony-Clie-branded version?  Or is it something else?
    Thanks
    Samizdat
    Post relates to: Pre p100eww (Sprint)

    wjwncpro wrote:
    Thanks WyreNut for your quick reply,
    I'm able to restore my system prior to trying to installing the update so that I don't lose anything with my current Desktop 4.2. I might be in a catch-22 as that, if I do a clean uninstall of v4.1 and install the v6.2, will I be able to hotsync my Sony Clie TH55 since it's not a Palm product but uses the Palm Desktop to sync???
    Any other ideas will be appreciated...
    Thanks
    I did a search of the Forum for "6.2 and Clie" and found several threads.  None were very promising.
    An example:
    http://forums.palm.com/palm/board/message?board.id=windows_hotsync&message.id=30065&query.id=52739#M...
    WyreNut
    I am a Volunteer here, not employed by HP.
    You too can become an HP Expert! Details HERE!
    If my post has helped you, click the Kudos Thumbs up!
    If it solved your issue, Click the "Accept as Solution" button so others can benefit from the question you asked!

  • Help needed upgrading from Windows 8 to XP for Conexant Sound Driver

    I upgraded from Windows 8 to XP and got everything else working except for the sound. I have scoured the internet and tried many versions of drivers from windows 7 ones to XP ones with no success. I tried older driver´s version as well.  After a reboot there is no sound device loaded in the control panel for sound. I have a C845D-SP4327SL  model laptop. Does anyone have any process to make this work that is proven? Thanks
    Vladimir Pineda.

    vpinedaq wrote:
    I upgraded from Windows 8 to XP and got everything else working except for the sound. I have scoured the internet and tried many versions of drivers from windows 7 ones to XP ones with no success. I tried older driver´s version as well.  After a reboot there is no sound device loaded in the control panel for sound. I have a C845D-SP4327SL  model laptop. Does anyone have any process to make this work that is proven? Thanks
    Vladimir Pineda.
    hi. if you want to that your sound device was in control panel after a reboot , here is only one solution for that, all you have to do is upgrade first  hdaudio bus controler. Driver must be copied first from computer with Vista os. if your xp is 32bit you have to copy this driver from any Vista x32 if  your xp is 64 bit then Vista must be x64 as well.  driver for forced upgrade through device menager you will find in any vista os  Windows--> System32-->DriverStore-->FileRepository-->hdaudbus​.inf9689af2f
    once copied that file from any computer equiped with Windows Vista , copy it on your desktop, next step go to the device menager  and find in system device tab 2 entries UUA High definition audio and update both by forced update. You have to point exactly where is located your driver copied from vista. after this update your sound device will be in the control panel and device manager always and permanent.
    I had the same problem with my xp instaled on satelite p500 and only this solution solved my problem with disappearing sound device after reboot.
    ps. if this solution help you please tell us about it. 
    Regards

  • Help needed exporting from Lightroom 4 to Photoshop CS6

    I'm running LR 4.4 and Photoshop CS6 on an iMAC and I'm having issues with the edit in photoshop option.  Used to be able to right click and image, go to Edit In and choose Photoshop CS6 and Photoshop would open and the image would open.  I could then make my changes and save them and those changes would copy back over to Lightroom.  Now when I choose Edit In>Photoshop, Photoshop opens but the image never opens.  It would prompt saying Open Anyway or Render using Lightroom.  If I clicked Open Anyway, the image would NOT open in Photoshop.  If I clicked Render using Lightroom, the image WOULD open in Photoshop.  Well now I've upgraded my software and it's no longer prompting me to Render using Lightroom.  Can someone help either fix the root probelm or tell me how to get my raw files to Render using Lightroom?

    Same problem here on the PC side.

  • Help needed upgrading from Vista to XP for Conexant Sound Driver

    I upgraded from Vista to XP and got everything else working except for the sound. I have scoured the interenet and tried many versions of drivers from Vista ones to XP ones with no success. Even though the drivers seem to update correctly when installed, after a reboot there is no sound device loaded in the control panel for sound. I have a P105-6197 model laptop. Does anyone have any process to make this work that is proven? Thanks
    Casey Jackson
    Solved!
    Go to Solution.

    Satellite P105-S6197
    Try these two sound drivers, Casey. The first one is newer (European date).
       Conexant Sound Driver for Windows XP, 3.44.0.0, 06/12/07
       sound-20071106151533.zip
       Conexant Sound Driver for Windows XP, 3.21.0.52, 15/10/07
       sound-20071015135316.zip
    -Jerry

  • Help needed! From Flash Professional to Edge Animate poll.

    If you have used Adobe Flash Professional and Adobe Edge Animate, please answer this 12-question poll. I'm studying in a university at the moment, and to complete the assignment that I have to do, I created a simple poll to find out, how users of Flash Professional can adapt to animating in Edge Animate. I'd appreciate it alot, if you answered this poll!
    https://docs.google.com/spreadsheet/viewform?formkey=dEZCdHp3SGVSOEdseEM2WG5MMk1xdUE6MQ
    Thank you!

    hi heldeJ,
    i just filled out your poll. I'm a flash developer who is moving to edge and would be interested in seeing the results of your poll. Good luck with it!
    best regards,
    -sharon

  • Web server and Exchange behind an ADSL router

    Hi all:
    I finally was able to go through the basic configuration of my new cisco ASA 5515 X (i'm completely new to cisco devices). 
    I also managed to create VPN's to my two Amazon VPC sites. This was particularly hard because my ADSL Router which this Cisco firewall is behind was making trouble.
    Finally, all I had to do is reboot the ADSL Router and it all started working, but I had a hard time to find out the source of the problem (the guys at Amazon did the job, to be honest)
    Now I face the next step, opening my web server and exchange server to the world. How is this done? Do I need to do something special because of the ADSL router?
    Thank you.

    On the ASA you'd do this with an ACL
    object-group service EXCHANGE_SERVICES tcp
     port-object ew www
     port-object eq imap
    ...etc etc
    access-list outside_in extended permit tcp any host 192.168.203.24 eq www
    access-list outside_in extended permit tcp and host 192.168.203.11 object-group EXCHANGE_SERVICES
    access-group outside_in in interface outside
    You'd also have to allow access in from your ADSL router.

  • 1841 ADSL Router - Forward GRE/PPTP query

    Hi,
    <br />
    <br />I have a customer that has an 1841 ADSL router as a backup to their main 10Mb ISP circuit. The customer has a windows server that they use for some remote access sessions with GRE/pptp. When the primary 10Mb link is in use, this works fine as the ASA on this link has a 1:1 NAT rule and allows port 1723 and protocol 47 through to this windows machine.
    <br />
    <br />When the 10Mb link is down, the customer would like to still be able to RAS into the windows machine but via the IP of the backup ADSL router (which is also connected to the ASA). Looking at various posts, I found that I need to have a static NAT for port 1723 on the inside to the dialer interface, which I have done - but I can't find how I would forward the protocol 47 traffic.
    <br />
    <br />I've attached a copy of the config from the ADSL router if anyone is interested.
    <br />
    <br />The IP of the windows RAS box is 192.168.247.113/24 on the DMZ of the ASA, which is translated as 81.X.X.X on the outside interface of the ASA.
    <br />
    <br />I hope that this makes sense - please let me know if you need any further information, and thanks in advance for any assistance.
    <br />
    <br />
    <br />1) XXX-XXX-ADSL-02-conf-03-02-09_netpro.txt
    <br />

    IP Protocol 47 which is GRE tunnel traffic. So there is VPN tunnel going through your device and all data going in that tunnel is translated as GRE traffic. You can only have one PPTP/L2TP connection through the PIX Security Appliance when you use PAT. This is because the necessary GRE connection is established over port 0 and the PIX Security Appliance only maps port 0 to one host.

Maybe you are looking for

  • Logic pro 9.1.6 (1700.43) crashes all the time under lion with mac mini server

    Hi, I run logic pro 9 with a mac mini server under lion 10.7.2 and it crashes all the time I get this crash report: Anyone knows how to solve this? Thanks Process:         Logic Pro [1877] Path:            /Applications/Logic Pro.app/Contents/MacOS/L

  • Best Buy sold me two Lenovo notebooks without left speakers!

    I camped out for 12 hours at the Best Buy in Brighton, MI and ended up purchasing two Lenovo g575-438343u notebooks for $180 each.  One of the first things I noticed was that the black seal was broken and there was clear packaging tape over it.  A st

  • JMS Listener Class Not found

    Hi I got the following error when starting weblogic 8.1 server: ####<Jul 14, 2004 5:24:15 PM PDT> <Notice> <Security> <sjcpc044> <myserver> <Thread-1> <<WLS Kernel>> <> <BEA-090082> <Security initializing using security realm myrealm.> ####<Jul 14, 2

  • Fault Policy framework doesnt work - SOA 11g

    Hi All, I am trying to excute a composite in which i had a business fault and i had the swicth condition based on reply. If reply is other than success or failure i will throw a fault Invalid data and the fault is catched by teh fault handler. but th

  • Initial download - update additional fields/execute additional funct.

    Hi All, We are in the process of uploading data from SAP system to CRM system as a initial download (Transaction code R3CS). Customer has a unique requirement of updating  additional fields (configurable fields) from ISU to CRM which are not covered