Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX - PIX VPNs over Multiple Interfaces to Multiple Sites

Status
Not open for further replies.

rrowland

Technical User
Jun 21, 2001
33
0
0
CA
I am having a problem establishing a access over a vpn connection that I have recently created.

The head site has a 6 port PIX 515E with the following interface config:

Int0 ---> Internet
Int1 ---> Corp Network
Int2 ---> Partner Network
Int3 ---> DMZ
Int4 ---> 2nd Internet
Int5 ---> Failover

We currently have a number of vpn's running with crypto maps pointing to the outside (Int0) interface and they are working fine. However, I just setup another crypto map that terminates on the Partner Network (Int2) interface. The tunnel is created and I have the proper access-list entries for both sites, but I can't ping any ip addresses on either side of the tunnel. I can use static nat's and bypass the tunnel but I can't seem to pass any traffic through the tunnel. All of the other vpns are setup the exact same way except that they use a different interface and they work fine.

Any thoughs,

Thanks

Richard Rowlandson

 
Do you have a "nat (int2) 0 access-list ..." on your configuration.
 
Also remember a static route from the pix to the other peer via the 2nd internet interface, otherwise the tunnel will be tried through the default route (intf0)

Jan
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top