06-25-2008 04:43 AM
Hi,
We have a PIX (6.3) L2L IPSec VPN tunnel. My question is if I let all the internet traffic from remote site to go to the central site, can the central site PIX allow the internet traffic to go out again?
Thanks, Leo
06-25-2008 07:16 AM
Not with pix 6, you need pix 7 to do this by hairpinning on the outside interface.
06-25-2008 04:57 PM
Thanks for the reply.
One more question here:
When I build up the IPSec VPN (PIX 6.3), both tow PIXs use command "route outside 0.0.0.0 0.0.0.0 GatewayIP" . But if I change it to "route outside PeerIP 255.255.255.255 GatewayIP", the VPN does not come up. Do you know why?
Thanks, Leo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide