Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

PIX520 v6.2 site-site with vpn3002

Trying to run vpn3002 in network extension mode. tunnel initiates but ip traffic does not seem to return. I have tried several static routes on the PIX. What is the correct static route for the private network on the vpn3002? Network works if PAT is enabled.

Cisco Employee

Re: PIX520 v6.2 site-site with vpn3002

The static route on the PIX will point to teh remote network and the gateway will be the PIX's default gateway on the outside interface (assuming the VPN is terminating on the outside interface that is). Similar to the default route actually, in fact if you have a default route in the PIX, and you don't have another route for the remote network or some part thereof pointing inside, then you shouldn't need a route on the PIX itself.

What you probably need is a route on your internal network pointing to the PIX inside interface. Your inside network hosts need to know how to get to the remote network, so make sure their default gateway is the PIX or they have a specific route for the remote network pointing to the PIX.

CreatePlease to create content