Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

How to design this network of StS tunnels

So I have a main site with a 506e on a full T1, soon to be tiered with another 506e to create a DMZ. I also have 4 remote sites on dsl/cable connections with 501s. I have a Site to Site VPN set up from each of the 4 smaller sites back to the main site, one of the uses of which will be voip traffic.

My problem is that each of the remote sites needs to be able to connect to each other remote site. The individual who initially designed this setup was planning on traffic from one remote site going back to the main site over its tunnel, and then out to the other remote site over ITs tunnel. The problem with that (unless I am wrong) is that it would require the PIX routing traffic out the same interface it came in on which it cannot do until 7.0 which is not available on the 506e.

The only other option I can think of is a full mesh network of sts VPNs but I am concerned about the ability of the 501 to handle that many simultaneous tunnels (I am also concerned about their plan to implement normal internet traffic and voip on dsl but we will have to look in to that at another time).

Will the 501 like handling all those tunnels? Is there another method for doing this that I am not thinking of?

The internet router at the main site is a 1700 and there is a layer 3 switch (35xx) also at the main site which could be used if needed.

thanks for your help


Re: How to design this network of StS tunnels


As per the data sheet it does support 10 Simultaneous VPN Peers.

would suggest to check this link for more info..

Simultaneous VPN peers: 10*

* Maximum number of simultaneous site-to-site or remote access IKE Security Association (SAs) supported

I would like u to check/verify the licensing part whether u got Restricted user license or an unrestricted user license in ur pix firewalls.


New Member

Re: How to design this network of StS tunnels

506e and 501s have an R license but 506 says IKE peers: Unlimited while 501 says 10.

Would you feel comfortable running 4 site-to-site VPNs from a 501 over a DSL connection? Think I will run into bandwidth problems since even more of it is being used by the tunnel's overhead?

I have never worked with the 501 before so I dont have any experience to draw on but something just didnt feel right when I realized I was faced with setting it up like this.


Re: How to design this network of StS tunnels

the biggest concern is the bandwidth i guess. in terms of the hardware, i mean the pix501, it should be fine.

i have a production 501 running 5 - 6 lan-lan vpns and it seems fine.