Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Access to DMZ from IPSEC Tunnel?

Status
Not open for further replies.

Iota

MIS
Sep 12, 2001
61
US

Hello... I managed to nail up an IPSEC tunnel btw a WG Firebox II and a PIX 515UR using a sample configuration from the website.

The dilemma is that I can only access the the 'inside' machines on the pix, when I also need to access the 'dmz' machines on the pix as well.

I've already setup access lists to and from the DMZ to the IPSEC Tunnel, but still no luck.

Most examples I nat (inside) 0 access-list to the list providing access via IPSEC; however cisco also says you need to use 'nat' to go from a higher security to a lower security interface, so I'm not sure what to do.

Of course, it could also be a problem on the WG box, but I'm 80-90% sure it's the pix. The WG is pretty straight forward (GUI) to setup.

Any help appreciated.

Thanks.

Iota
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top