[fw-wiz] LAN-LAN VPN using PIXes and a dialup connection

From: Stefan Pantke (seaside.ki_at_mac.com)
Date: 06/25/04

  • Next message: ArkanoiD: "[fw-wiz] Future and past firewalls (was "firewalls comparison")"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 25 Jun 2004 07:24:04 +0200
    
    

    Hi,

    I'm new to this list, so please be patient ;-)

    I have two LANs which are connected by a IPsec VPN tunnel
    through 2 PIX 501 which connect to the internet by some dialup
    line (ISDN).

    The tunnel itself performs well. Traffic passes correctly.

    The problem: Even if both LANs are switched off, the dialup routers
    establish new connections. Since this is traffic on IP protocol 50,
    it should be related to the IPsec connection.

    The questions:

    - Why do the PIXes establish VPN connections, even if no LAN
    traffic has to be router through the VPN to the ohter LAN?

    - How to configure the PIXes for a VPN tunnel using a leased line -
       and not to connect each minute again...

    Stefan

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: ArkanoiD: "[fw-wiz] Future and past firewalls (was "firewalls comparison")"

    Relevant Pages

    • Re: Losing Static IP Address / Changing to Automatic (expects DHCP)
      ... >Peer to peer network with no router or ICS-configured computer or other DHCP ... >Somebody comes in with a laptop that has the same IP address set up as is on ... addresses, and control connections, rigorously. ... are a good idea for larger LANs, or for LANs where connections come and go, and ...
      (microsoft.public.windowsxp.network_web)
    • Re: About windows xp home firewall
      ... ICF works and is supported on LAN connections. ... >>>to the www directly via modem and doesn't support LANs. ...
      (microsoft.public.windowsxp.network_web)
    • RE: Making 2 ends meet
      ... You can create a VPN tunnel between the two LANS and share resources. ... If the 2 LANS do not presently have Internet connectivity, then you will need to obtain whatever ... '--'routers, bridges, gateways etc. ...
      (microsoft.public.win2000.networking)
    • RWW VBScript Error: An internal error has occurred
      ... connections. ... office with a SBS 2003 server and 6 remote offices running XP SP2 ... connecting via VPN to the domain so they can be accessed through RWW. ... I have done some checking and the VPN tunnel is ...
      (microsoft.public.windows.server.sbs)