12-19-2007 10:27 AM - edited 02-21-2020 03:26 PM
Hi, I have a PIX 515E with version 7.x. It has two different internet links connected, one is used to get access to Internet from inside and the other I would like to use only for dynamical VPN clients.
How I have to configure this to make the VPN traffic, that comes from the second link go back for same interface? in actual configuration I have a default route pointing to first link.
I need use âsame-security-traffic permit intra-interfaceâ command to do this?
Thanks,
12-19-2007 10:53 AM
same-security-traffic permit intra-interface will not help in this case since the pix can only have 1 default gateway. You would have to know the source address of the vpn clients to be able to route to them from the second interface.
12-20-2007 06:06 AM
The problem is that this links are DSL with dynamic IP addressing.
12-20-2007 10:57 AM
I think RRI, reverse route injection is the answer to your question.
Antonis
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide