Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN client thru pix, is this possible?

Status
Not open for further replies.

bigdog175

IS-IT--Management
Nov 7, 2000
41
US
I manage a few remote sites via VPN everything works great from outside using VPN client. What I'm trying to accomplish is being able to use the client to connect to a remote site while being behind a pix. Scenario: Sites A,B,C are all secured by pix if I'm not at A,B or C I connect fine, when I'm at A,B or C I can't connect either of the other 2 sites, but need to occasionly, is this possible what are my options, any input is welcome. The remote sites are for different companies so a pix to pix tunnel is not really an option, unless I can turn the link on/off. Thanks in advance.
 
How do I go about setting this up? Is a issue of setting up PAT/NAT or making static mappings?
 
Yes I am trying to VPN from my personal laptop to another network. When I am connected anywhere outside of any of the 3 networks everything is great but when I'm behind any of the 3 pix fw (all of which are 525's 6.1(4) I can't establish a link.
 
Ok, on PIX you need to open UDP port 500 and IP protocol 50. If the PIX is running 6.2.X or below you also need a static translation for the IPSec peer behind the PIX. Now if you are running 6.3.X then you don't need a static translation, but you need to enable fixup protocol esp-ike.

Alternatively, you can enable NAT-Traversal (NAT-T) on the headend device, that is the IPSec peer where the VPN client connects to.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top