Pix Site to Site w/ Remote VPN Clients

Answered Question
Jan 29th, 2008
User Badges:

I accidentally posted this question in the incorrect forum earlier today. I could not find a way to move it or delete it, so I apologize for the duplication.


I have established a site to site VPN between 2 Pix 506e's. I setup the VPN tunnle using the VPN wizard, and it appears to work properly. 




However, I also have users who VPN directly into the PIX via PPTP or a Cisco VPN client. Those users are not able to access resources that are on the other end of the VPN tunnel. It appears as though the map ACL that triggers packets to be sent across the tunnel is not being matched, but I have not been able to figure out how to get this to work properly. 



PIX A has a local subnet of 192.168.1.x/24. PIX B has a local subnet of 192.168.2.x/24. Traffic between these 2 subnets flow across the tunnel. However, when someone establishes a VPN into PIX B, they are also put into the 192.168.2.x/24 subnet, but they are unable to access anything in the 192.168.1.x/24 subnet. Is something like this possible? The config from PIX B is attached. 

Any help you could offer would be greatly appreciated.




Thanks,




-Steve





Attachment: 
Correct Answer by ajagadee about 9 years 5 months ago

This is not possible with Pix and 6.3 version of code.


If you are running 7.0 or higher on the Pix, then, Yes this is possible. Please refer the below URL for configuration details. The feature that you are looking for is called "intra-interface".


http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805734ae.shtml


Also, 7.0 and higher are not supported on Pix 501, 506 and 520.


Regards,

Arul


** Please rate all helpful posts **

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
ajagadee Tue, 01/29/2008 - 15:35
User Badges:
  • Cisco Employee,

This is not possible with Pix and 6.3 version of code.


If you are running 7.0 or higher on the Pix, then, Yes this is possible. Please refer the below URL for configuration details. The feature that you are looking for is called "intra-interface".


http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805734ae.shtml


Also, 7.0 and higher are not supported on Pix 501, 506 and 520.


Regards,

Arul


** Please rate all helpful posts **

Actions

This Discussion