Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

VPN Design question

Hello,

I need to open a site-to-site VPN between 2 PIxs v7.2.1. But on one PIX, the "private network" to be accessed via the VPN is on interface outside eth 0 (security level 0). The VPN tunnel starts from a DMZ interface, eth2 (security levl 2). So I need to apply nat 0 on interface outside, and I would like to know if it can work, because it seems strange, or if I need to change the security levels ?

Thank you,

Patrice

2 REPLIES
Bronze

Re: VPN Design question

Your scenario is indeed strange. Usually, the private networks are either behind the firewall or on the DMZ segment. But I believe the PIX 7.x supports the concept of haripinning, that is the traffic received on one interface can be sent out the same interface (this was not the case with 6.x). In your case, if the routing is properly configured, the tunneled packets can be sent out the outside interface.

New Member

Re: VPN Design question

Hello,

Thank you a lot for your answer.

Patrice

110
Views
0
Helpful
2
Replies
CreatePlease login to create content