Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

501Newby How to VPN SHO thru DSL gateways

Want vpn for remote W2K access/mgnt. Would appreciate any advice. Here is the current setup.

Office LAN switch 192.168.1.0-> <--192.168.1.1--PIX--192.168.20.2-> <-x.x.20.1--NAT,DSL,STAT--64.161.125.2-->INET<--67.112.194.66--NAT,DSL,STAT--192.168.1.1---> <--192.168.1.0--LAN switch Home.

Building configuration...

: Saved

:

PIX Version 6.1(2)

nameif ethernet0 outside security0

nameif ethernet1 inside security100

enable password SVtsrBPtYQH379XQ encrypted

passwd SVtsrBPtYQH379XQ encrypted

hostname pixfirewall

domain-name ciscopix.com

fixup protocol ftp 21

fixup protocol http 80

fixup protocol h323 1720

fixup protocol rsh 514

fixup protocol rtsp 554

fixup protocol smtp 25

fixup protocol sqlnet 1521

fixup protocol sip 5060

fixup protocol skinny 2000

names

name 192.168.1.0 LAN

name 192.168.20.0 WAN

name 192.168.1.2 Mother

name 67.112.194.66 BayoVista

pager lines 24

interface ethernet0 10baset

interface ethernet1 10full

icmp permit host BayoVista echo-reply outside

mtu outside 1500

mtu inside 1500

ip address outside dhcp setroute

ip address inside 192.168.1.1 255.255.255.0

ip audit info action alarm

ip audit attack action alarm

pdm location Mother 255.255.255.255 inside

pdm location BayoVista 255.255.255.255 outside

pdm logging informational 100

pdm history enable

arp timeout 14400

global (outside) 1 interface

nat (inside) 1 0.0.0.0 0.0.0.0 0 0

timeout xlate 0:05:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00

timeout uauth 0:05:00 absolute

aaa-server TACACS+ protocol tacacs+

aaa-server RADIUS protocol radius

http server enable

http LAN 255.255.255.0 inside

no snmp-server location

no snmp-server contact

snmp-server community public

no snmp-server enable traps

floodguard enable

no sysopt route dnat

telnet timeout 5

ssh timeout 5

dhcpd address 192.168.1.10-192.168.1.30 inside

dhcpd lease 3600

dhcpd ping_timeout 750

dhcpd auto_config outside

dhcpd enable inside

terminal width 80

Cryptochecksum:4d29a0f49b4a32de243ad147531e26d4

: end

[OK]

2 REPLIES
Cisco Employee

Re: 501Newby How to VPN SHO thru DSL gateways

Do you really have to have 192.168.1.x at both LAN's, can you change your hom eLAN to be something else, it will make things a LOT easier in the long run.

If you can change your home LAN to some other network, then you can just set up a normal LAN-to-LAN tunnel as described here:

http://www.cisco.com/warp/public/110/38.html

The only difference is that on your NAT devices on the outside of each PIX, you'll need a static one-to-one NAT translation for the actual IP address of the PIX, and then point each other PIX to that NAT address in the crypto configuration.

If you can't change your home LAN from 192.168.1.x, then it gets difficult and you'll have to use the new features in 6.2 code and follow this sample config:

http://www.cisco.com/warp/public/707/vpn_pix_private.html

Once again though you'll need a static NAT translation for each PIX so the the other PIX can route to it.

New Member

Re: 501Newby How to VPN SHO thru DSL gateways

Glenn,

I don't have a 501 at home yet $$$. So what I need for now is (I think?) for the office PIX to let me in from my home static IP.

Thanks alot.

Todd

93
Views
0
Helpful
2
Replies