Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IPSec to PIX VLAN Interface

Hi,

I was wondering if anyone has tried implementing IPSec VPNs to a VLANed interface. I have 2 DSL connections each with only on static address. I want to pass them through a Cisco router, NAT them, and then forward the IPSec request to one of 2 Logical (VLAN) interfaces on the outside interface of the PIX. Is this something that will work?

Kelvin

  • Other Security Subjects
3 REPLIES
Silver

Re: IPSec to PIX VLAN Interface

Re: IPSec to PIX VLAN Interface

You mean .. you have your PIX outside interface connected to a switch as trunk. You have 2 VLANs linked to the outside interface. You have your VLANs interfaces NATed on the router to public addresses. You want to terminate the Ipsec on one of the VLANs .. Am I correct ..

If this is the case then it should be OK .. just make sure the PIX and router can pass IPsec and also make sure your PIX allows NAT-Traversal. The device at the other end also needs to support nat traversal.

isakmp nat-traversal 20

I hope it helps ... please rate if it does !!!

New Member

Re: IPSec to PIX VLAN Interface

Hi guys thanks for the reply, I actually got a PIX in house this evening so I will be upgrading the PIX 7.0(4) to 7.1 and then simulating the environment here at my office. I will let you know what happens over the next day or so.

Kelvin

96
Views
0
Helpful
3
Replies