Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Help, anyone knows how to config site-to-siteVPN w/Pix515E&LinksysBEFSX41?

Hi Guys,

Please help, is anyone tested or knows how to configure the Pix 515E site-to-site VPN with Linksys BEFSX41? As of this time, i'm using cisco vpn client to have a vpn tunnel (running and operational) to our head office but we are planning to implement site-to-site VPN, Pix515E at Head Office and Linksys BEFSX41 on our remote branches. Thanks in advance and more power!


Re: Help, anyone knows how to config site-to-siteVPN w/Pix515E&L


Please have a look at this URL for cisco PIX configuration... the other end can be a router/linksys or any other device..

For linksys configuration, u can probably google it....

Hope this helps.. all the best.. rate replies if found useful..


New Member

Re: Help, anyone knows how to config site-to-siteVPN w/Pix515E&L


Thanks for your help, I'll do some experimentation on this. Also, is it possible to configure my pix515E for Site-to-Site VPN and at the same time for VPN Client-to-Site VPN?

More power!



Re: Help, anyone knows how to config site-to-siteVPN w/Pix515E&L


Yes you can have both, here's an example:

access-list nonat permit ip

access-list nonat permit ip

access-list 100 permit ip

access-list 101 permit ip

ip local pool raspool mask

nat (inside) 0 access-list nonat

sysopt connection permit-ipsec

crypto ipsec transform-set esp-3des esp-md5-hmac

crypto dynamic-map dynmap 100 set transform-set

crypto map 1 ipsec-isakmp

crypto map 1 match address 100

crypto map 1 set peer

crypto map 1 set transform-set

crypto map 65535 ipsec-isakmp dynamic dynmap

crypto map interface outside

isakmp enable outside

isakmp key address netmask

isakmp identity address

isakmp nat-traversal

isakmp policy 1 authentication pre-share

isakmp policy 1 encryption 3des

isakmp policy 1 hash md5

isakmp policy 1 group 2

isakmp policy lifetime 86400

vpngroup address-pool raspool

vpngroup dns-server

vpngroup wins-server

vpngroup default-domain

vpngroup split-tunnel 101

vpngroup idle-time 1800

vpngroup password

NOTE - If you need access to the internet whilst connected to your internal network using the vpn client then you'll need

to use the 'split-tunnel' command, I personally don't allow this for security reasons but added this so that you know it can

be done.

Hope this helps and let me know if you have any further questions - please rate posts if it helps.