cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
305
Views
0
Helpful
1
Replies

Can't get access to internet from remote site via IPsec

hartleyp
Level 1
Level 1

I wonder if anyone can help.

I have 2 sites connected via IPsec tunnel. Remote site connects to main site and all is OK.

Remote site is supposed access the net via main site.

Cannot get traffic beyond the mail site LAN to the net. I've learnt that you cannot route in then out of the same port (may be the reason). On the same LAN there is another firewall that gives normal internet access. I have tried adding a route to the PIX for the IPsec remote gateway, plus an additional default route out of the internal interface to the main firewall.

No joy, I don't think the PIX is even passing frames out of the internal inteface.

Access list on the PIX is forcing traffic down the tunnel for remote site, fine. NAT is enabled for other addresses although this would have to route out the same interface.

ISP

¦

Gateway

¦

¦--------------------¦

¦ ¦

PIX Firewall

¦ ¦

¦------------------¦--------------------¦

¦ ¦ ¦

1 Reply 1

cjacinto
Cisco Employee
Cisco Employee

The PIX would not redirect packets it receives on its interface out the same interface.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: