Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pix vpn client gateway

Status
Not open for further replies.

krismorrison

IS-IT--Management
Dec 20, 2005
4
US
Quick question if anyone can help.....

I have a PIX 515e (ios 6.3) using vpn clients to access internal LAN.

On our internal LAN, we have a dedicated DS3 connection to a separate network, (the DS3 router is also the main gateway that allows LAN nodes to access local and remote LAN).

Our PIX vpn clients can access everything except for the remote network connected via DS3..

Is it possible to have the VPN clients use the DS3 router as its main gateway?

Thanks in advanced
 
Sounds like a routing issue. You're PIX acts as the gateway for your VPN connections and it can't redirect to the DS3 connection, at least this is what it sounds like. But your internal users are pointed to another gateway besides the PIX correct? Does anyone use the PIX for a gateway on the inside network?

"I can picture a world without war. A world without hate. A world without fear. And I can picture us attacking that world, because they'd never expect it."
- Jack Handey, Deep Thoughts
 
the DS3 router is also the main gateway that allows LAN nodes to access local(??) and remote LAN....."

So is the DS3 Router directly behind the PIX?

Code:
Internet ---> PIX ----> DS3Router ----> LAN
                           |
                           |
                          WAN                               
                           |
                         Branch LAN
Or is the PIX Inside and Main LAN on the same subnet?
Code:
Internet ---> PIX ----> LAN <----> DS3Router
                                       |
                                       |
                                      WAN       
                                       |
                                   Branch LAN

Does the DS3 Router know how to get to the VPN Client Network (IP Pool)?

Are you using Split Tunnelling? If so does this include the Main Local LAN and the Branch LAN?

If you do a traceroute from the Branch LAN to the VPN Pool Network where does it die?

Is the Branch LAN traffic exempt from NAT (nat 0) when going to the VPN Pool Network?
 
Thanks for the responses,

Does anyone use the PIX for a gateway on the inside network? - No inside users use the PIX for their default gw.

Our gw is a 2600 series router that splits traffic destined to the remote LAN to the DS3 router, and traffic for the internet to the PIX.

Im basically trying to get the VPN client traffic to point to the 2600 router if possible.

Current config is :

Local LAN---->2600-->PIX-->internet
|
DS3 router
|
Remote LAN

Thanks again


Kris

Kris
 
Put a route into the PIX pointing to the network you want your VPN users to see.

"I can picture a world without war. A world without hate. A world without fear. And I can picture us attacking that world, because they'd never expect it."
- Jack Handey, Deep Thoughts
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top