Re: Setup Remote VPN on PIX 501
- From: roberson@xxxxxxxxxxxx (Walter Roberson)
- Date: Thu, 23 Mar 2006 15:48:49 GMT
In article <1143126551.698668.141300@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>,
<tom.weber@xxxxxxxxx> wrote:
I'm trying to configure a remote VPN where clients can connect using
the VPN client and have access to the internal network. I'm new to the
PIX, and seem to be having some trouble.
All configuration is done through the PDM.
I used the Wizard to create the vpn server.
Internal Network 192.168.1.0/24
VPN IP Pool 10.10.10.1 - 10.10.10.11
And for the exemtion I just clicked finish, so they will have access to
the internal network.
The client can authenticate with the VPN server, and be assigned an ip
address, however cannot ping or access any internal clients, nor ping
the 192.168.1.1 internal interface on the PIX. Where am I going wrong?
The text version of your configuration (with passwords scrubbed)
would help.
I am not going to try to guess what the PDM might or might not have
done on your behalf -- too many different screens and you would
have to describe each configuration step and each drop-box selection
and so on for me to be able to replicate what you ended up with.
The text configuration is *much* easier to answer questions about.
My -guess- is that the PDM didn't happen to turn on
sysopt connection permit-ipsec
but I don't have enough information to be sure.
The client can authenticate with the VPN server, and be assigned an ip
address, however cannot ping or access any internal clients, nor ping
the 192.168.1.1 internal interface on the PIX. Where am I going wrong?
For your purposes you should assume that the VPN clients will
never be able to ping the PIX inside interface IP. [If you *really*
needed them to be able to do that, it would be possible to configure,
but it's a relatively advanced configuration and seldom worth the
bother.]
.
- Follow-Ups:
- Re: Setup Remote VPN on PIX 501
- From: tom . weber
- Re: Setup Remote VPN on PIX 501
- References:
- Setup Remote VPN on PIX 501
- From: tom . weber
- Setup Remote VPN on PIX 501
- Prev by Date: Re: Moving Config from PIX 515 to 515e
- Next by Date: Re: 2 PIX Same COnfig, though 1 not connected to 'real' outside? Does not work?
- Previous by thread: Setup Remote VPN on PIX 501
- Next by thread: Re: Setup Remote VPN on PIX 501
- Index(es):
Relevant Pages
|
Loading