×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Rerouting VPN connection over the same interface

Unanswered Question
Jul 13th, 2006
User Badges:

Hello


I have a PIX 501 firewall which has configured several IPSec VPN connetion to other locations.

For mobile user RAS connetions with PPTP configuration exist on the same firewall. There is a IP pool with a independent IP-segment for PPTP users.

The access from the PPTP user to local ethernet segment works fine, but they are not able to access the other locations which are connected over a IPSec. The IPSec and PPTP access works over the same interface (outside).

I configured a new IPSec rules for the PPTP IP segment on both sides.


I saw in the log the error message that there is no route for the demanded connetion between PPTP and the branch.


How is the correct configuration for a such need?


regards

Pascal


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
m.sir Fri, 07/14/2006 - 01:58
User Badges:
  • Gold, 750 points or more

This may not be possible using PIX 6.3. PIX 6.3 does not route traffic received on one interface back out the same interface. Its possible with PIX 7.0 ..but there is no support PIX 7.0 for 501 boxes

M.

grant.maynard Tue, 07/18/2006 - 13:32
User Badges:
  • Silver, 250 points or more

As you say, this is defintely not possible in this case.

A PIX515 with v7.2(1) and "same-security-traffic permit intra-interface" would do it.

Actions

This Discussion