RE: [fw-wiz] PIX to PIX IPSec Tunnel Through a PIX
From: Melson, Paul (PMelson_at_sequoianet.com)
Date: 03/03/04
- Previous message: Mike Meredith: "Re: [fw-wiz] Multiple small switches vs. a single big one; Granularity of control"
- Maybe in reply to: Al Cooper: "[fw-wiz] PIX to PIX IPSec Tunnel Through a PIX"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: "Al Cooper" <alc@tlynx.com>, <firewall-wizards@honor.icsalabs.com> Date: Wed, 3 Mar 2004 08:51:03 -0500
I see big problems with PAT, especially if it's a global PAT through the interface of the 515E. I would create a static NAT on the 515E for the 501. Then it's just an issue of allowing the right protocols. Minimally, you will need to allow ISAKMP (UDP/500) and ESP through the 515E in both directions.
PaulM
-----Original Message-----
I am attempting to establish a IPSec tunnel where 3 pix's are involved. I
have a PIX 506E on one end of the tunnel. On the other end is a PIX 515E
running PAT, that needs to pass through the IPSec tunnel to an internal 501
where the tunnel will be terminated (through the Border firewall and
terminated on the Departmental firewall).
I am finding very little information on the proper way to set-up this
network configuration. I have read that I may need to use NAT instead of
PAT, and use the Nat-T function on the 515E. But other than that I am lost.
Can you Firewall experts lead me in the right direction?
Thanks in advance for your help,
Al Cooper
_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Previous message: Mike Meredith: "Re: [fw-wiz] Multiple small switches vs. a single big one; Granularity of control"
- Maybe in reply to: Al Cooper: "[fw-wiz] PIX to PIX IPSec Tunnel Through a PIX"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|