PPTP users over IPsec

Unanswered Question

Dear Experts,
Please refer the attached scenario.

I have formed an IP sec Tunnel and advertised the LAN subnets & its working fine.
But i have another requirement
External users are connected to site A pix using pptp vpn and once they connected they will get ip range of 192.168.5.1-5.100.My requirement is these subnets 192.168.5.x has to access site B's LAN subnets (10.2.2.0/24) Is this possible, If so what configurations i have to do on PIX. Please help me!
Thanks,
Pramod

Attachment: 
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Nagaraja Thanthry Tue, 08/03/2010 - 21:24
User Badges:
  • Cisco Employee,

Hello,


Please try the following:


-- Add a nonat rule for traffic from 192.168.5.x subnet to 10.2.2.x subnet

-- Add the crypto access-list for traffic from 192.168.5.x subnet to

10.2.2.x subnet


-- Add a nonat rule for traffic from 10.2.2.x subnet to 192.168.5.x subnet


http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configura...

_example09186a00804675ac.shtml


Hope this helps.


Regards,


NT

Jitendriya Athavale Wed, 08/04/2010 - 00:29
User Badges:
  • Cisco Employee,

you will need to do u turning too


since u have a pix can you plz mention the version u r running, as on pix on certain versions u turning is not supported

Jitendriya Athavale Wed, 08/04/2010 - 03:28
User Badges:
  • Cisco Employee,

in that case you will not be able to do u turning or hair pinning


so i guess we will have to figure out a way around

Jitendriya Athavale Wed, 08/04/2010 - 04:32
User Badges:
  • Cisco Employee,

yes i understand so u have pptp and site site terminating on the same interface right

Nagaraja Thanthry Wed, 08/04/2010 - 06:12
User Badges:
  • Cisco Employee,

Hello,


Code version above 7.2(4) will work and you will be able to do the U-turn.


Hope this helps.


Regards,


NT

Jitendriya Athavale Wed, 08/04/2010 - 23:04
User Badges:
  • Cisco Employee,

you will still need it... in any case i would still recommend you upgrade because 6.3 is a ancient code which is soon going into the books and you dont want to play catching up ...


u turning is just one small feature that you get in newer code, one of the most important tool that i personally find the most useful as tac engg is packet tracer,


as such the structure of the code is new and diff compared to 6.3

..

Actions

This Discussion