Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

501Newby How to VPN SHO thru DSL gateways

Want vpn for remote W2K access/mgnt. Would appreciate any advice. Here is the current setup.

Office LAN switch> <--> <-x.x.20.1--NAT,DSL,STAT-->INET<--,DSL,STAT--> <-- switch Home.

Building configuration...

: Saved


PIX Version 6.1(2)

nameif ethernet0 outside security0

nameif ethernet1 inside security100

enable password SVtsrBPtYQH379XQ encrypted

passwd SVtsrBPtYQH379XQ encrypted

hostname pixfirewall


fixup protocol ftp 21

fixup protocol http 80

fixup protocol h323 1720

fixup protocol rsh 514

fixup protocol rtsp 554

fixup protocol smtp 25

fixup protocol sqlnet 1521

fixup protocol sip 5060

fixup protocol skinny 2000


name LAN

name WAN

name Mother

name BayoVista

pager lines 24

interface ethernet0 10baset

interface ethernet1 10full

icmp permit host BayoVista echo-reply outside

mtu outside 1500

mtu inside 1500

ip address outside dhcp setroute

ip address inside

ip audit info action alarm

ip audit attack action alarm

pdm location Mother inside

pdm location BayoVista outside

pdm logging informational 100

pdm history enable

arp timeout 14400

global (outside) 1 interface

nat (inside) 1 0 0

timeout xlate 0:05:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00

timeout uauth 0:05:00 absolute

aaa-server TACACS+ protocol tacacs+

aaa-server RADIUS protocol radius

http server enable

http LAN inside

no snmp-server location

no snmp-server contact

snmp-server community public

no snmp-server enable traps

floodguard enable

no sysopt route dnat

telnet timeout 5

ssh timeout 5

dhcpd address inside

dhcpd lease 3600

dhcpd ping_timeout 750

dhcpd auto_config outside

dhcpd enable inside

terminal width 80


: end


Cisco Employee

Re: 501Newby How to VPN SHO thru DSL gateways

Do you really have to have 192.168.1.x at both LAN's, can you change your hom eLAN to be something else, it will make things a LOT easier in the long run.

If you can change your home LAN to some other network, then you can just set up a normal LAN-to-LAN tunnel as described here:

The only difference is that on your NAT devices on the outside of each PIX, you'll need a static one-to-one NAT translation for the actual IP address of the PIX, and then point each other PIX to that NAT address in the crypto configuration.

If you can't change your home LAN from 192.168.1.x, then it gets difficult and you'll have to use the new features in 6.2 code and follow this sample config:

Once again though you'll need a static NAT translation for each PIX so the the other PIX can route to it.

New Member

Re: 501Newby How to VPN SHO thru DSL gateways


I don't have a 501 at home yet $$$. So what I need for now is (I think?) for the office PIX to let me in from my home static IP.

Thanks alot.