Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pix 515 and Routing all VPN traffic to Pix

Status
Not open for further replies.

DHungate

MIS
Sep 10, 2001
1
CA
I would like to configure my Pix to recieve VPN traffic from a remote destination and then forward traffic destined to the Internet that came through the VPN tunnel to the Internet.

Most VPN devices such as Sonicwall and Symantec's Firewall have an option to route all the traffic through, in the Sonicwall it shows up as: "Route all internet traffic through this SA"

This works pretty good but when it gets to the Pix it says the traffic has a bad SPI, here is some of my VPN config on the Pix:
access-list pixtolondon permit ip 10.0.0.0 255.0.0.0 10.12.18.0 255.255.255.0
nat (inside) 0 access-list pixtolondon
crypto map tosonicwall 20 ipsec-manual
crypto map tosonicwall 20 match address pixtolondon
crypto map tosonicwall 20 set peer xxx.xxx.xxx.xxx
crypto map tosonicwall 20 set transform-set SIRBasic
crypto map tosonicwall 20 set session-key inbound esp xxx cipher xxxxxxxxxxxxxxxxx
crypto map tosonicwall 20 set session-key outbound esp xxx cipher xxxxxxxxxxxxxxxxx
crypto map tosonicwall interface outside
 
Sorry but it is not possible on the PIX. It cannot route packets back on the same interface they arrived. A work around is to setup a proxy server on the internal LAN behind the PIX and point the remote PCs to the proxy server to go to the Internet. The traffic from remote sites will be decrypted at the PIX and sent to the proxy who inturn will send the Internet request through the PIX. A cisco router or VPN concentrator does not have this limitation.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top