Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

PIX 501 to 501 vpn

I am trying to setup my first 501 to 501 vpn and I'm having some difficulties. I have attached both configs. Site A is a PIX dedicated to this VPN, and Site B is the remote sites primary firewall. Any help would be greatly apprectiated!! I am setting this up for VoIP. Thanks!!!

8 REPLIES
Silver

Re: PIX 501 to 501 vpn

I have the following observations regarding your configuration of pix 501 at site A:

1) There is no default route. You probably require this to establish reachability to the other PIX.

2) You have an access-list 101 bound to your outside interface but no such access-list is configured.

3) You have a route configured for NEX-MIA but you do not require this as all traffic to NEX-MIA will be encrypted and sent over the tunnel. Please remove this route statement.

New Member

Re: PIX 501 to 501 vpn

I have completely re-built the 501 at site A. I can now successfully connect and route to site B, but when I try to route from site B back to A I am unsuccessful.

Any suggestions on site B? Thanks!!!

New Member

Re: PIX 501 to 501 vpn

Sorry... hit post too quick! Here are the attachements.

Silver

Re: PIX 501 to 501 vpn

What tests are you performing that are failing? At a first glance everything seems to be in order on your Pix 501 - Site B.

New Member

Re: PIX 501 to 501 vpn

I attempted to FTP to a server on site A and to ping a server on site A. I do not need access list entries for these items since I am going over VPN... correct?

Silver

Re: PIX 501 to 501 vpn

Yes the 'sysopt connection permit-ipsec' statement ensures that all decrypted traffic does not have to be checked against the ACLs.

So you are able to connect to Site B from Site A but the other way is not happening ... correct? Have you tried accessing multiple servers in Site A?

New Member

Re: PIX 501 to 501 vpn

Well I can't believe that I didn't check other servers, but I must not have since I can ping any other one... I will have to try and figure out what is going on with this particular server. Thanks for confirming that everything was ok with my configs!

Silver

Re: PIX 501 to 501 vpn

Check to see if this server has a firewall enabled that is preventing ping requests and other connection requests. Glad to hear everything is working fine.

Please rate helpful posts.

124
Views
9
Helpful
8
Replies
CreatePlease to create content