Re: [fw-wiz] full IPSEC tunnels on PIX and NAT ...
From: Miha Vitorovic (mvitorovic_at_nil.si)
Date: 12/03/03
- Previous message: Adel Guia Cruz: "[fw-wiz] How AAA in PIX Firewall ?"
- In reply to: peter bartoli: "[fw-wiz] full IPSEC tunnels on PIX and NAT ..."
- Next in thread: peter bartoli: "Re: [fw-wiz] full IPSEC tunnels on PIX and NAT ..."
- Reply: peter bartoli: "Re: [fw-wiz] full IPSEC tunnels on PIX and NAT ..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: firewall-wizards@honor.icsalabs.com, firewall-wizards-admin@honor.icsalabs.com Date: Wed, 3 Dec 2003 08:38:03 +0100
Peter,
For one thing, the PIX can not route out through the same interface, the
packet comes into the device. So, if your VPNs terminate on the outside
interface (and they do according to the config), there is no way that the
PIX will route the packets to the Internet, which also connected to the
outside interface. That's just the way PIXen are :-)
Regards,
--- Miha Vitorovic Inženir v tehničnem področju Customer Support Engineer NIL Data Communications, Tivolska cesta 48, 1000 Ljubljana, Slovenia Phone +386 1 4746 500 Fax +386 1 4746 501 http://www.NIL.si firewall-wizards-admin@honor.icsalabs.com wrote on 29.11.2003 21:39:55: > > ... hello, and thank you in advance for any help you might be able to > offer. > > I've got a PIX that I'm using for just a couple of clients to VPN into, > and would really like to get full tunnels working so that all their > traffic goes over the tunnel and then out to the internet. > > I've scoured all of Cisco's documentation, and can't find anything I'm > doing wrong, but I seem to be stuck with the following kind of error > message: > _______________________________________________ firewall-wizards mailing list firewall-wizards@honor.icsalabs.com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Previous message: Adel Guia Cruz: "[fw-wiz] How AAA in PIX Firewall ?"
- In reply to: peter bartoli: "[fw-wiz] full IPSEC tunnels on PIX and NAT ..."
- Next in thread: peter bartoli: "Re: [fw-wiz] full IPSEC tunnels on PIX and NAT ..."
- Reply: peter bartoli: "Re: [fw-wiz] full IPSEC tunnels on PIX and NAT ..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|