Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Tough VPN-to-PIX question

Status
Not open for further replies.

veneficuss

IS-IT--Management
May 29, 2002
16
0
0
US
PIX vpn and inside interface look like this :

|Gateway|--|concentrator|--|pix|--|routerA|--|routerB|

subnets connected to routerA :
192.168.100.0
192.100.100.0
subnets connected to routerB :
192.7.7.0
194.6.6.0

On PIX : all subnets were statically applied so that VPN users could use the actual addresses (no translations).

On Concentrator : static routes for all the above nets were created and point to the PIX

The Problem :
We have taken all of the PIX restrictions off, to allow IP, TCP & ICMP access. VPN clients can go through the concentrator and reach routerA and all directly connected nets.
Users CANNOT reach routerB or any of those nets.

HEEEELP

tried everything. Why cant users hop to the next router? We are able to ping routerB networks from all routerA networks. Anyone have any ideas?

everyone is using RIP v1/2
 
HI.

You can try to redesign the network, and put the VPN box behind the pix (inside), or better on a dedicated pix interface (or 2).
This will better protect the VPN box from external attacks, and can solve some of your problems without punching too many holes in the firewall.

What do you think?

Can you provide more details about your problem?

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top