Cisco VPN question
Moderator: Dictators in Training
Cisco VPN question
My office is using Ciscos VPN client to connect to our clients networks. The problem we have is that once connected to the VPN our work stations are effectively disconnected from our own network and we can only see machines on the client network.
What I'm wondering is if it's possible to be connected to both at once with single nic cards at each workstation. The biggest problem I see is that in many cases our clients are using the same ip range on their networks that we use on ours, and this would obviously make being on both at once problematic because the workstation would see duplicated IP addresses. I'm willing to renumber our network, but I'm not sure if the disconnect from our network by the vpn client is due to addressing or simply an automatic function of the vpn client it's self.
What I'm wondering is if it's possible to be connected to both at once with single nic cards at each workstation. The biggest problem I see is that in many cases our clients are using the same ip range on their networks that we use on ours, and this would obviously make being on both at once problematic because the workstation would see duplicated IP addresses. I'm willing to renumber our network, but I'm not sure if the disconnect from our network by the vpn client is due to addressing or simply an automatic function of the vpn client it's self.
Raymond S. Kraft wrote:The history of the world is the history of civilizational clashes, cultural clashes. All wars are about ideas, ideas about what society and civilization should be like, and the most determined always win.
Those who are willing to be the most ruthless always win. The pacifists always lose, because the anti-pacifists kill them.
There is a setting in the client to allow access to both networks I believe. I don't have the client in front of me but it "should" install a virtual adapter that gets an IP on the remote network and then your NIC should keep it's local IP so you can access both networks. You may need to add a route statement as well.
Tossica wrote:There is a setting in the client to allow access to both networks I believe. I don't have the client in front of me but it "should" install a virtual adapter that gets an IP on the remote network and then your NIC should keep it's local IP so you can access both networks. You may need to add a route statement as well.
Nerd
Zanchief wrote:Tossica wrote:There is a setting in the client to allow access to both networks I believe. I don't have the client in front of me but it "should" install a virtual adapter that gets an IP on the remote network and then your NIC should keep it's local IP so you can access both networks. You may need to add a route statement as well.
Nerd
oh shit, marketable knowledge, who wants that?
You probably will need to re-number your network, however. Seeing the same IPs at both ends could definitely confuse it, as if it sees a request for, say, "telnet 192.168.1.1", it won't know which adapter to send the request out to.
If you're currently using 192.168, just switch to the 10.xxx.xxx.xxx space, or visa versa. Assuming most of your user computers are all getting their IPs via DHCP, it shouldn't even be that big of a project. Couple hours, tops, after hours one night unless you've got a much bigger setup there than it sounds like.
-Arlos
If you're currently using 192.168, just switch to the 10.xxx.xxx.xxx space, or visa versa. Assuming most of your user computers are all getting their IPs via DHCP, it shouldn't even be that big of a project. Couple hours, tops, after hours one night unless you've got a much bigger setup there than it sounds like.
-Arlos
Thanks Tossica even though now I feel like someone looking for thier car keys while having them in hand. I did find a client with a different ip range, but noticed after checking the allow local lan access flag the info about the connection still shows that local land is disabled. It might be something I need to have the clients enable server side.
And yea Arlos the ip renumber is a given, once I get it working with the clients with different ip ranges. I'll probably have to do it after hours so people don't whine, but shouldn't take me to long.
And yea Arlos the ip renumber is a given, once I get it working with the clients with different ip ranges. I'll probably have to do it after hours so people don't whine, but shouldn't take me to long.
Raymond S. Kraft wrote:The history of the world is the history of civilizational clashes, cultural clashes. All wars are about ideas, ideas about what society and civilization should be like, and the most determined always win.
Those who are willing to be the most ruthless always win. The pacifists always lose, because the anti-pacifists kill them.
Jay wrote:Use a treo to connect to the client network and it'll free up your computer.
This wouldn't really accomplish my goal which is to be able to send files from another machine on our network to a client machine from any workstation.
Raymond S. Kraft wrote:The history of the world is the history of civilizational clashes, cultural clashes. All wars are about ideas, ideas about what society and civilization should be like, and the most determined always win.
Those who are willing to be the most ruthless always win. The pacifists always lose, because the anti-pacifists kill them.
Lueyen wrote:Jay wrote:Use a treo to connect to the client network and it'll free up your computer.
This wouldn't really accomplish my goal which is to be able to send files from another machine on our network to a client machine from any workstation.
erm, do you really need vpn then?
it sounds more like you need a ftp server than anything else
An ftp server wouldn't really work, this is more for our tech support. We generally use either PC Anywhere or VNC to make direct connections to individual machines to fix problems or physically show the people who call in how to do something. What we do run into is that when we want to lookup something on our network (such as source code stored on one of our servers) or send something to them that is not on the workstation we have to disconnect from the VPN and either look up the info or copy the files to the workstation so that they can be sent from the local drive once reconnected.
I did find some information on configuration on Cisco's site that seems to point toward some options that have to be enable on the host side at our clients location.
I did find some information on configuration on Cisco's site that seems to point toward some options that have to be enable on the host side at our clients location.
Raymond S. Kraft wrote:The history of the world is the history of civilizational clashes, cultural clashes. All wars are about ideas, ideas about what society and civilization should be like, and the most determined always win.
Those who are willing to be the most ruthless always win. The pacifists always lose, because the anti-pacifists kill them.
Re: Cisco VPN question
Lueyen wrote:My office is using Ciscos VPN client to connect to our clients networks. The problem we have is that once connected to the VPN our work stations are effectively disconnected from our own network and we can only see machines on the client network.
What I'm wondering is if it's possible to be connected to both at once with single nic cards at each workstation. The biggest problem I see is that in many cases our clients are using the same ip range on their networks that we use on ours, and this would obviously make being on both at once problematic because the workstation would see duplicated IP addresses. I'm willing to renumber our network, but I'm not sure if the disconnect from our network by the vpn client is due to addressing or simply an automatic function of the vpn client it's self.
Not really sure if your question got answered but some food for thought and how I allow this at the company I work at.
For starters, you allowing both networks to be "connected" (ie. client and your native lan) means you can become a gateway between the two networks. This can very likely break SLA's or create other problems (e.g. you infect your client network with a virus, cause harm to client network ,etc etc). They more then likely do NOT want you to be connected to both networks at the same time. If they know what they are doing, you won't be able to "hack" the cisco vpn client to allow what you're asking. However you could like at other options (add a nic, etc) and even this may be thwarted by the cisco client.
Depending on how the customer configured the cisco client, it should be stopping all network access while VPN is running to ALL other networks but it's own (own meaning the customer network). This is an option via the client config from the server, I doubt you'll be able to adjust much on the cisco client unless the customers don't know how to use it.
WebEx would be a great option and not all that expensive. We use that and a combo of citrix to complete tasks like this.





