cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
202
Views
0
Helpful
1
Replies

PIX VPN

london.ism
Level 1
Level 1

Hi all,

I would like to implement the following config on a 501 Pix: on the outside interface of my PIX which is in location b, I have two vpn tunnels going to two separate locations, a and c. Now I would like, through these tunnels, a to be able to contact c through b. Is this possible? Is this one of the cases that requires double NAT-ing? Are there any issues with PIX 501 to receive and send a packet on the same outside interface?

Many thanks

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

Elena

"Are there any issues with PIX 501 to receive and send a packet on the same outside interface?"

Unfortunately it won't work with a Pix 501. The feature you need is called "hairpinning" but this is only supported on pix v7.x code and later (also supported on ASA devices). The pix 501 cannot run v7.x code.

Pix 515E, 525 and 535 are the only pix firewalls that can be upgraded to v7.x code.

Alternatively a router can support hairpinning.

Jon

Review Cisco Networking products for a $25 gift card