Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Internet access out from remote systems.

Status
Not open for further replies.

tanker135

MIS
Sep 8, 2003
14
US
Folks,

Presently I have a simple site to site VPN using 501's. It works great. My single access list is "access-list 101 permit ip 172.18.128.0 255.255.255.224 172.18.0.0 255.255.192.0" I need to have users at the 172.18.128.0 network (remote network) go out my firewall here at HQ. FW's address is 172.18.1.120. How can I do this with the least trouble? Thank you.
 
You will not be able to achieve this task, the PIX is not able to route packets back on the same interface they arrived. You need to end the tunnel at a router or VPN 3K instead.
 
Or, just close of the remote pix with acl's and then put up a proxy server at your site, so that they will surf/ftp from that proxy, if you use a MS IAS you will also get the benefit of the AD integration.

Jan


Network Systems Engineer
CCNA/CQS
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top