Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

pix bizarre vpn issue


i m being established a vpn tunnel bewtween two pix (515--> 501). If i configure the vpn tunnel with the encryption domain ---, it works perfectly. However if i use the encryption domain 194.42.../27 --, it doesn t work !! 194.42.../27 range belongs to a puclic network

in fact 194.42.../27 is dmz

Can we establish a vpn tunnel with encyption domain public(dmz)--private ?


New Member

Re: pix bizarre vpn issue

I hope outside interfaces of both the PIXs are configured with public IP and if they are not then they might be connected with a point to point link right.

When you establish VPN tunnel between two PIXs there is a logical path created between both the devices.

And after that you can communicate with any source to any destination subnet.

Hope that helps,


Suresh Jain

New Member

Re: pix bizarre vpn issue

the pix doesn't care if its public, private or other wise, you need to make sure that you have the appropriate routing and nat statements.

When you say it doesn't work, what do you mean, do you see any errors in your "Debug crypto iskamp" or debug crypto ipsec sa

Also, im assuming that the private address that worked was (inside) and the new tunnel your creating is from (dmz)

make sure you have nonat configured for traffic from (dmz) to remote (inside)

on the remote side, make sure you have routes pointing your (dmz) public addressing out the interface that facilitates the vpn tunnel to head office.

we would need more infomation like configs and/or diagrams to help further.

remmeber the check the nonat/nat statements on both ends..

New Member

Re: pix bizarre vpn issue

here is the config. if i do ping inside from the pipx 501 the vpn process start and from the other pix i get the logs attached to this email.

The thing is i can t start the vpn process from the other pix (515) if i do ping dmz, i get:

%PIX-6-110001: No route to from yy.yy.yy.60 (dmz ip address from the dmz interface (yy.yy,yy.32/27)

New Member

Re: pix bizarre vpn issue

i resolved the problem. it was about the route between the pix and my network. And also i added

global (outside) 1 interface

nat (dmz) 0 access-list inside_nat0_outbound