cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
186
Views
0
Helpful
1
Replies

PIX to PIX VPN's on mutiple Interfaces

mark.ramsey
Level 1
Level 1

Here's the gig,

We have a PIX 525, I have 10 remote PIX 501's. The 501's attach via the intenet to a T1 circuit attached to the PIX 525. Interesting traffic is encrypted and passed via VPN internally.

The problem is, I have now over provisioned my internet connection and wish to off load some (and the kicker is some not all) of the VPN clients to another circuit/port on the firewall. After much research I have come to a simple observation. When creating access lists which define my "interested" data I can only specify one Access-list via the "nat (inside) 0 access-list 100".

Please tell me it isn't so!!!!!!!!!!!!!!!!!! Ummm and if it is what would you rcommend (other than the obvious "move all the VPN's to the same interface")

Thank you for any assistance you would be willing to offer.

Mark

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

If you terminate some of the tunnels on say, a dmz1 interface, you just do:

> nat (dmz1) access-list 101

and then have ACL 101 specify your interesting traffic for those VPN's.

Terminating tunnels on two different interfaces is no problem, you can see how it's done here:

http://www.cisco.com/warp/public/110/client-pixhub.html

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: