Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN Connection

Status
Not open for further replies.

bobo0605

MIS
Dec 4, 2003
71
US
I have two sites with two different subnets ( 192.168.1.0 and 2.0 ). I currently have a VPN connection into the 192.168.1.0 network that is just for administrators. The company is starting to get more mobile users so i need to expand this feature so here is my question. I would like to VPN into one site and be able to access information and applcations over the T1 line rather than creating two different VPN connection to both sites. I would also like the peeple to log in with their windows login to get there security clearences. I know i need a RADIUS server for this but do i need to add some route statements and access-list in order for the single VPN connection to go over the T! line. The IP address given with the VPN is 10.0.0.0. Hope this is not to confusing and any help would be appreciated.
 
It would be more helpful if you were to post if:


192.168.1.0 and 2.0 are two different locations joined by a site to site VPN and the ips of the outside interfaces for both sites. I assume 1.0 and 2.0 are the inside interfaces for two different pix's?, or are both inside subnets/VPNs on one pix?

 
The two locations are connected with a t1 line. Each site has it's own internet connection and it's own pix. I would like to VPN into the 192.168.1.0 pix and be able to pick up the network security and be able to access all the network resources on both networks.

 
How many interfaces does each firewall has and which interface are you terminating the VPN on each firewall


 
I have two interfaces one interface is for the external world and the other is the internal that is connected to switch.
 
If you are terminating the VPN on the outside interface and VPN clients need to establish their connection on the same interface you will not be able to do it with version 6.x

You might have to upgrade one of the images to 7.x or if you need more flexibility you might look into VPN concentrators

Hope that helps
 
Yes that helps. I'm currently at version 6.3 and i'm in the process of upgrading. I'm used to the switch and router commands so i'm getting a feel for the pix stuff.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top