cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
0
Helpful
7
Replies

PIX 501 VPN

aseychell
Level 1
Level 1

Hi there,

I have a PIX 501 connected to the internet which is currently on the edge of the network. I have a client to which I want to connect using VPN so when PC on my network side request a particular IP, traffic passes through th tunnel. The other company sent me theit VON settings and I was able to configure them in the PIX using the Easy-VPN Remote wizard. The tunnel came up ok but all the other internet traffic stopped working. I had to remove the tunnel for the internet to work again. Is this something normal or am I mistaken in using something which I shouldnt?

7 Replies 7

jackko
Level 7
Level 7

split tunneling needs to be configured on the server end.

So the internet cannot be accessed from my tunnel side? I have to use the internet at the main office?

no, it means that split tunneling needs to be configured on the server end.

split tunneling enables the hardware client to be able to determine what sort of traffic should traverse the vpn and what not.

If Im understanding this right you connect pix to a concentrator using Easy vpn. Then the concentrator must be configured with split tunneling

Configuration / User management / Groups / Modify XXX / Split tunneleling Policy.

There you can choose: "Tunnel everything" or "Only tunnel networks in the list"

You have a description what to do when you get there.

Hope this helps

If Im understanding this right you connect pix to a concentrator using Easy vpn. Then the concentrator must be configured with split tunneling

Configuration / User management / Groups / Modify XXX / Split tunneleling Policy.

There you can choose: "Tunnel everything" or "Only tunnel networks in the list"

You have a description what to do when you get there.

Hope this helps

According to step #6 in this document:

http://www.cisco.com/en/US/partner/tech/tk583/tk372/technologies_configuration_example09186a00800945cf.shtml

Split-tunneling cannot be specified the normal way in the concentrator for EasyVPN.

I have not found any docs on CCO to explain how this is done, although the above doc says it is suppported...