HI,
yizhar, slachance & sunyasee Thank you very much!
I worked it out. The problem is in our subnet there is a other cisco router which be set as all pcs defualt gateway, so when ping from branch to a pc in this net, so this why only one way traffic like
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest 0
#pkts decaps: 3, #pkts decrypt: 3, #pkts verify 3
other side is
#pkts encaps: 3, #pkts encrypt: 3, #pkts digest 3
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify 0
after I change the pc defualt gatetway to my PIX, it works well! just like the text book. So what we do is jsut add a routing entry in the Cisco router.
So I have one more question: If I don't change the config at router, may I config the PIX's inside port work like a router, just as if the package is the interesting traffic it will pass through the PIX to PIX tunnel, and if the package is point to an other subnet in inside, it will be send to the router.
Thanks again!
oh
yizhar, slachance & sunyasee Thank you very much!
I worked it out. The problem is in our subnet there is a other cisco router which be set as all pcs defualt gateway, so when ping from branch to a pc in this net, so this why only one way traffic like
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest 0
#pkts decaps: 3, #pkts decrypt: 3, #pkts verify 3
other side is
#pkts encaps: 3, #pkts encrypt: 3, #pkts digest 3
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify 0
after I change the pc defualt gatetway to my PIX, it works well! just like the text book. So what we do is jsut add a routing entry in the Cisco router.
So I have one more question: If I don't change the config at router, may I config the PIX's inside port work like a router, just as if the package is the interesting traffic it will pass through the PIX to PIX tunnel, and if the package is point to an other subnet in inside, it will be send to the router.
Thanks again!
oh