RE: [fw-wiz] PIX Routing Issue

From: Wes Noonan (mailinglists_at_wjnconsulting.com)
Date: 01/23/04

  • Next message: Peter Bruderer: "Re: [fw-wiz] Netscreen reverting to default config"
    To: "'Josh Welch'" <jwelch@buffalowildwings.com>, <firewall-wizards@honor.icsalabs.com>
    Date: Thu, 22 Jan 2004 21:00:22 -0600
    
    

    Are you permitting the traffic to be passed to/from the VPN to/from the
    remote networks? Remember, you need an ACL that specifies the "interesting"
    traffic that the PIX will pass through the VPN connections. This all beyond
    the routing that must be configured to occur. Everything needs to be able to
    route end to end. That means you can't just add routes at the PIX. You have
    to add routes to the remote networks across the VPN on all the other
    routers/firewalls.

    HTH

    Wes Noonan
    mailinglists@wjnconsulting.com
    http://www.wjnconsulting.com

    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com [mailto:firewall-wizards-
    > admin@honor.icsalabs.com] On Behalf Of Josh Welch
    > Sent: Thursday, January 22, 2004 15:47
    > To: firewall-wizards@honor.icsalabs.com
    > Subject: [fw-wiz] PIX Routing Issue
    >
    > Okay, I apologize if this is confusing, I'm still hammering it out in my
    > skull. I've got a number of remote sites to be set up with PIX501s to VPN
    > into a PIX515. Behind the PIX515 is LAN2, then a Linux box, LINUXFW2,
    > seperating LAN2 from LAN1, and another Linux box, LINUXFW1, serving as the
    > Gateway for LAN1 and our DMZ, where our mail server sits. So, our clients
    > at
    > the remote sites through a squid proxy 've set up in LAN2. The squid proxy
    > is using LINUXFW2 as its default gateway, that traffic is being routed out
    > through LINUXFW1, that's working great. Now, I need to be able to get
    > those
    > clients to be able to hit our mail server in the DMZ, without using split
    > tunnels. I've tried doing one of these on the PIX515:
    > route inside X.X.X.68 255.255.255.255 10.0.2.11 1
    >
    > This didn't do it, and in my thinking, it should. I also tried:
    > route outside X.X.X.68 255.255.255.255 10.0.2.11 1
    >
    > Which I didn't think was right, and it didn't work either. I put together
    > a
    > little ASCII diagram, don't know if it helps or hurts matters, but here it
    > is. THanks for taking the time on this.
    >
    > Josh
    >
    > |REMOTE |__INTERNET__| PIX515 |_LAN2_|LINUXFW2 |
    > |X.X.X.X| |X.X.X.88 10.0.2.10| |10.0.2.11|
    > | |
    > |10.0.0.11|-|
    > |
    > |
    > INTERNET_____ | LINUXFW1 |____LAN1_______|
    > |X.X.X.93 10.0.0.10|
    > | X.X.X.78 |
    > |
    > DMZ
    > MAILSERVER
    > X.X.X.68
    >
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Peter Bruderer: "Re: [fw-wiz] Netscreen reverting to default config"

    Relevant Pages

    • RE: Two VPN clients on one computer
      ... If you need to connect to different remote networks via VPN on a regular ... > Is it possible to run two VPN clients on one computer? ... In any case if you search Google for "VPN Mesh internetwork security" ...
      (Security-Basics)
    • Re: Desperate Housewife Win 2000 Server vpn mess !
      ... Your routing table shows two default routes with the same metric. ... Can you make a VPN connection to the server from a local LAN client? ...
      (microsoft.public.win2000.ras_routing)
    • Re: IP routing on VPN
      ... my VPN clients can't connect to the VPN server. ... Frame router that routes to subnets 192.168.30.1 ... How do the VPN clients know to get to the outside NIC? ... >> I have a RRAS Server setup as a VPN with two NICs. ...
      (microsoft.public.windows.server.networking)
    • Re: IP routing on VPN
      ... >my VPN clients can't connect to the VPN server. ... >Frame router that routes to subnets 192.168.30.1 ... >How do the VPN clients know to get to the outside NIC? ...
      (microsoft.public.windows.server.networking)
    • Re: Split tunnel
      ... you could specify that the connection does not use the gateway provided by ... needed to connect to the networks accessed via the VPN ... >> specific routes for the VPN. ... >>>I have a client that is using a PPPTP VPN to connect to there network. ...
      (microsoft.public.win2000.ras_routing)