We have PIX 515 on the hub site and 5 PIX 501's configured as spoke sites. There are approximately 40-50 remote users who are able to connect to the hub site with the vpn client without problem. But these clients cannot connect to spoke sites.
How should I configure the hub/spoke site in order to get this functionality?
Re: Vpn client connecting to spoke site through hub
The PIX will not redirect. It is a firewall, not a router.
If you can't set the clients to connect directly to the spoke sites, which would probably be the easiest solution, you could investigate the possibility of bouncing the clients off a router on the inside of the hub pix.
If there is a big enough user license on the 501's set vpngroup statements there for direct connection from clients. Remember, there is a limit of 5 concurrent vpn connections to a 501.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...