Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX VPN Routing

Status
Not open for further replies.

siverson

Vendor
Dec 1, 2005
1
US
Hello all,

I am working on a PIX/VPN problem that is now getting the best of me and leaving me empty handed. I know Cisco well enough to get around most problems, but I am now at a point where what I thought I have done every which way is not working. To make matters worse.. the client's Cisco support contract is expired and it is going to take a bit to get it back..

Here is my issue, and thanks in advance to anyone that has any input for me.

I have a remote office that is connected via static DSL through a VPN3002 unit back to the main office which is running a PIX 515E.

From the remote office I can get to the main office network just fine in terms of remote desktop to servers on that network, and network shares. If I try from the main office to reach anything on the remote network it fails. I can’t even ping the remote network or router from the PIX.

This tells me I am missing a return routing statement on the PIX.

Here are the network specs:

Remote Office

192.168.2.0 / 255.255.255.0 Network
VPN3002 IP = 192.168.2.1

Main Office

10.0.0.0 / 255.255.255.0 Network
PIX 515E = 10.0.0.10


I have re-written this config more times that I care to remember.. and it just doesn’t want to work.

For a little background, I am working with something another vendor wrote and never worked properly…There are other VPN’s that work and I have tried to match those routes and statements but to no avil.

Here is a link to the config before I started messing with it.


Any help would be great ! Thanks a lot !
 
You probably have the 3002 in EzVPN Client Mode. Change it to Network Extension Mode.

In Client Mode, the 3002 acts as a PAT Firewall. This means all hosts behind it take on the ip address assigned to the 3002 by the Firewall's address pool. You can not ping it or ping through it.
Network Extension mode is just like a Lan2Lan VPN. It doesn't ask for an IP address. It uses the existing one (i.e, 10.1.1.1/24). You just needto make sure you main site knows to go to the PIX for the 3002 Internal Network. You may also have to put a static route on the PIX to point to the 3002.
i.e., If the PIX outside ip is 1.2.3.4 and the 3002 network is 10.1.1.0/24
route outside 10.1.1.0 255.255.255.0 1.2.3.4
(it should just go through the tunnel)

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top