Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

which one should be the default gateway, vpn 3000 or pix?

In the following doc:http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/3_6/getting/gs1und.htm,

VPN Concentrator configured in parallel with a firewall. and I don't find router in private segement. so which one should be the default gatways for the hosts in private segment. Pix couldn't do this, because it couldn't redirect(reroute) packets that sended to vpn clinet to vpn3000 even you add static route in it.

so I think we should select vpn3000. can the vpn3000 redirect(reroute) the packets that sended to internet to pix? if it can, there would be two default routes in vpn3000? because the remote vpn clients have various public addresses, so we should have default route to outside router(public segment), on the other side ,local hosts want to go everywhere through pix, so vpn3000 should have default route to pix in order to reroute those packets. Two default route is impossible,I am really puzzled.

of course if there is a router in the pivated segment, this is not a prolbem, router will reroute packets correctly.

The key point is that the pix couldn't redirct(reroute) packets like a router.

can someone help me?

another question:

If there isn't pix,just internet----router---vpn3000---private lan, can the hosts in private lan vist the internet and vpn clients (lans) at the same time? router can do this, can the vpn3000 works like a router in such condition?

2 REPLIES
Bronze

Re: which one should be the default gateway, vpn 3000 or pix?

The PIX should be the default gateway for the clients since they are immediately off that segment.

New Member

Re: which one should be the default gateway, vpn 3000 or pix?

Thanks. but I think your answer is about how to set 'tunnel default gateways' in vpn3000.

My question is how to select default gateway for the hosts and servers in private segement(central office). If it is still pix, I don't think the hosts in central office could visite remote hosts through vpn3000, because pix couldn't reroute(redirect) the traffic even there is a static route in the pix. The key is pix don't acts like router.

94
Views
0
Helpful
2
Replies
CreatePlease to create content