Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Managing one of 2 VPN-connected PIXes

Status
Not open for further replies.

chripa

Programmer
Mar 27, 2008
10
AT
Hi!

I have set up a site-to-site VPN connection between 2 PIXes (on different locations) using the VPN Wizard. PIX1 is in the Main Office, PIX2 is in the Little Office. Everything works, but I can NOT manage the PIX2 in the Little Office (on the remote side) from the Main Office (on the "local" side).

What must I do to be able to manage the remote PIX2 from the Main Office?

Please help - it's urgent.


Regards,
chripa
 
What version of code? How are trying to manage the remote PIX? Through the tunnel or SSH or ASDM? Were you ever able to manage it? Do you have any access to it now?

 
Both PIX 501 have version 6.3 and I manage them in the LAN with the PDM web interface (other methods like telnet, etc works as well.)

We have 2 locations with one PIX each. Both PIXes are connected via VPN (with the "site-to-site" VPN-Wizard)

My problem is, that I can access every host of location2 (through the VPN Tunnel) from the LAN on location1, but NOT the PIX. In other words: I want to manage the PIX on location2 when I am behind the PIX in location1.

Hope this helps! :)
 
You need to use the "management-access inside" command and then make sure you are permitted by the pdm for your address scheme. You can then connect to the inside interface of the firewall.
 
I have followed all your advices, but it's still not able to manage the Remote PIX from the other location. [thumbsdown]

Is there something else, I have to enable, to manage to remote PIX? [neutral]
 
Of course - but please tell me how to do this -. I have never done such things,,,
 
From command line do a "sh run"

You will need to copy the output to a text editor like notepad. Once you have the data there scrube the config of any IP addresses, usernames passwords that you do not want displayed to the public. Once you feel your config is scrubbed post it here.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top