Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PIX to PIX VPN's on mutiple Interfaces

Here's the gig,

We have a PIX 525, I have 10 remote PIX 501's. The 501's attach via the intenet to a T1 circuit attached to the PIX 525. Interesting traffic is encrypted and passed via VPN internally.

The problem is, I have now over provisioned my internet connection and wish to off load some (and the kicker is some not all) of the VPN clients to another circuit/port on the firewall. After much research I have come to a simple observation. When creating access lists which define my "interested" data I can only specify one Access-list via the "nat (inside) 0 access-list 100".

Please tell me it isn't so!!!!!!!!!!!!!!!!!! Ummm and if it is what would you rcommend (other than the obvious "move all the VPN's to the same interface")

Thank you for any assistance you would be willing to offer.


Cisco Employee

Re: PIX to PIX VPN's on mutiple Interfaces

If you terminate some of the tunnels on say, a dmz1 interface, you just do:

> nat (dmz1) access-list 101

and then have ACL 101 specify your interesting traffic for those VPN's.

Terminating tunnels on two different interfaces is no problem, you can see how it's done here:

CreatePlease login to create content