Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Static mappings and conduits needed for VPN passthrough

Status
Not open for further replies.

jgassner2

Technical User
Sep 19, 2003
26
0
0
US
Hello everyone,
Forgive me if this a long.
I have an issue where a client needs to connect to a remote site through a pix. I have posted this problem before and I greatly appreciate all of the replies I have gotten. Unfortunately, the client was out of the country for over a month and I had no idea that the problem still existed. So here is what I have found out so far through the many hours of research. I had allowed access from the remote site for VPN protocols and still have not had much success. I also made sure the fixup protocol pptp 1723 was enabled since I have the newer version of code. The client can connect but after a while the connection would drop. After reading some more I found out in my Cisco book that I have to use static mappings and ACLs to allow any traffic in from a lower security interface to a higher security interface. Is this also true for VPN related traffic. If so, please let me know.

Thanks
 
If you are trying to pass through GRE traffic to a server where all the VPN will be terminated then you will need static address, and since most people NAT everything behind the firewall you will need static mapping for that server to exist.

Hope that helps
 
Good point horus42. I never thought of it that way. I am finally get a test PIX to work with so that way I try different things without jepordizing connectivity. If anyone needs to see a config let me know.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top