Re: Need Site to Site VPN Help. How to route to a network not directly connected through VPN



Evolution wrote:
I don't think this should be too hard, but I have a general question. I
setup a Site to Site VPN between a Pix 515 and Pix 501(Easy Enough).
The hard part is getting the internal networks to talk. I network the
PCs is on connects to a Proxy Server, which then connects to the PIX
515. The PC network is 10.1.0.0/16 and the Proxy Server has an
interface on that LAN, and the network directly connected to the PIX
515(192.168.100.0/24) as well. The remote LAN that I'm trying to access
is 10.4.1.0/24. My ACL for NONAT is setup between 10.1.0.0 and
10.4.1.0. I'm not sure if I have to NONAT between 192.168.100.0 and
10.4.1.0, and then add a route into the Proxy Server, or if I keep it
the way I have, and then add some sort of "route inside or outside"
command to the PIX. Any help would be greatly appreciated. A diagram of
the config can be found here:
http://img140.imageshack.us/img140/1298/vpnhelp2qw.jpg

THANKS for the HELP!


You'll need a router behind the PIX on the internal network and point the routes on the PIX to the router on the inside.

Chuck
.



Relevant Pages

  • PIX 515E dropping existing TCP connections
    ... I recently took over administration of a PIX 515E. ... network, and VPN to the PIX to access a private network. ... When the VPN is connected, I can SSH to hosts on the private network. ... PIX drops the connection after transferring just a few kilobytes. ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] bypassing PIX limitation
    ... setup another Pix box who's sole purpose is to connect to the ... Hopefully the following information will be clearer: The network behind ... assign the outside ip block from the partner to your global ... Can packets going into a VPN tunnel be NATed? ...
    (Firewall-Wizards)
  • [fw-wiz] Followup: An interesting VPN problem
    ... - Repeat above steps for the remote PIX, ... all traffic on the remote network is pushed ... > (including the traffic that should ultimately end up on the Internet). ... > that to work (using source routing), but I'd like to use a peripheral ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Re: IP aliasing behind a PIX
    ... > network behind the PIX, but ... >> IPs behind a PIX firewall. ... >> network, the aliases work fine (i.e., the machines are accessible using ...
    (Firewall-Wizards)
  • Re: Cisco 501 Pix - Cable Modem - Wireless Router.....
    ... Network Student wrote: ... Gateway PC with a wireless network card. ... Plug the PIX 501 into the cable modem. ...
    (comp.security.firewalls)