Changed Inside IP subnet on PIX 501, cant VPN to PIX 515



So I have a PIX 501 that I configured to use the 10.14.0.0/16 subnet.
Outside Interface is DHCP, ComCast Internet
All is well, connects, traffic passes and we are good.

I have a 1600 series router with Firewall IOS, that I configured to use the
10.11.0.0/16 subnet
Outside interface it DHCP/PPPoE, AT&T DSL Internet
All is well, connects, traffic passes and we are good.

Both are connected via preshared-keys, DefaultRAGroup.
All of the ACLs include both 10.11.0.0/16 subnet and 10.14.0.0/16 subnet

So I want to Replace the Router with the PIX.
I Disconnect the Router,
Reconfigure PIX with 10.11.0.0/16 addresses.
Reboot everything so the MAC addresses are flushed
and it wont connect.

I've turned on all the debugging on the 501 PIX and its like its not seeing
any Interesting traffic to initiate the VPN Link.

doing the show cry map, I see the ACL with the Source/Dest Subnets and they
are correct. though the hitcnt is 0

Seems like if there was an Issue on the PIX 515 side not liking the new
client on the old subnet at least I would see the connection attempt on the
PIX 501 side..


Suggestions?

Scott<-


.



Relevant Pages

  • Re: Cisco PIX 501: Cant ping global IP-Adress from NATed IP
    ... on the 'static' statement for the server, add the 'dns' keyword. ... The catch is that the two interfaces cannot have the same IP subnet, ... of the external interface. ... then the PIX wouldn't know which interface to send it towards. ...
    (comp.dcom.sys.cisco)
  • Re: ISA 2004 Routing
    ... goes from the interface where you receive the packet to the interface on ... your network where you want the packet to go. ... > connected to my PIX. ... > I have one NIC setup in the 192.168.1.0 subnet and another NIC setup on ...
    (microsoft.public.isaserver)
  • Re: changing pix internal address
    ... I have rewritten the config file to reflect what I feel the configuration should look like. ... I cant just ditch the .1 subnet, I got printers workstations, other routers and servers stuck in there. ... :I want to reconfigure the pix to be on 192.168.41.x but not cause ... :can I bind two addresses to the pix internal interface as an intrim ...
    (comp.dcom.sys.cisco)
  • Re: SBS2k3 Server not responding to VPN Clients & Advice on SP2 Firewall configuration for VPN u
    ... what subnets the public and private interfaces of the Pix ... goes to your gateway router and the Pix private interface ... is in the 192.168.1.x subnet (where your SBS external ...
    (microsoft.public.windows.server.sbs)
  • Re: changing pix internal address
    ... :I want to change the internal ip address of my pix, moving the subnet it ... :can I bind two addresses to the pix internal interface as an intrim ... Really, if you already have a LAN router, it's easier to toss on ...
    (comp.dcom.sys.cisco)

Loading