07-23-2006 01:05 AM
Hello,
I need to open a site-to-site VPN between 2 PIxs v7.2.1. But on one PIX, the "private network" to be accessed via the VPN is on interface outside eth 0 (security level 0). The VPN tunnel starts from a DMZ interface, eth2 (security levl 2). So I need to apply nat 0 on interface outside, and I would like to know if it can work, because it seems strange, or if I need to change the security levels ?
Thank you,
Patrice
07-28-2006 06:33 AM
Your scenario is indeed strange. Usually, the private networks are either behind the firewall or on the DMZ segment. But I believe the PIX 7.x supports the concept of haripinning, that is the traffic received on one interface can be sent out the same interface (this was not the case with 6.x). In your case, if the routing is properly configured, the tunneled packets can be sent out the outside interface.
07-30-2006 09:34 AM
Hello,
Thank you a lot for your answer.
Patrice
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: