I wonder if anyone can help.
I have 2 sites connected via IPsec tunnel. Remote site connects to main site and all is OK.
Remote site is supposed access the net via main site.
Cannot get traffic beyond the mail site LAN to the net. I've learnt that you cannot route in then out of the same port (may be the reason). On the same LAN there is another firewall that gives normal internet access. I have tried adding a route to the PIX for the IPsec remote gateway, plus an additional default route out of the internal interface to the main firewall.
No joy, I don't think the PIX is even passing frames out of the internal inteface.
Access list on the PIX is forcing traffic down the tunnel for remote site, fine. NAT is enabled for other addresses although this would have to route out the same interface.
ISP
¦
Gateway
¦
¦--------------------¦
¦ ¦
PIX Firewall
¦ ¦
¦------------------¦--------------------¦
¦ ¦ ¦