RE: [fw-wiz] Cisco VPN Client Behind a Cisco PIX or Router

From: Melson, Paul (PMelson_at_sequoianet.com)
Date: 09/01/04

  • Next message: Marcus J. Ranum: "[fw-wiz] Re: Flawed Surveys [was: VPN endpoints]"
    To: "Al Cooper" <alc@tlynx.com>, <firewall-wizards@honor.icsalabs.com>
    Date: Wed, 1 Sep 2004 15:01:28 -0400
    
    

    First, the 515E that the VPN client connects to should probably have
    'isakmp nat-traversal' set. That might take care of it right there.
    Also, if the PIX that the VPN client sits behind has a global NAT
    assigned to 'interface outside', consider creating a separate NAT
    address on the outside subnet for global NAT to use. (This won't be
    possible if you only have a single IP address available, like in a SOHO
    / residential setup.)

    PaulM

    > -----Original Message-----
    > I have configured a Cisco VPN Client (4.6.00) to connect to
    > a Cisco PIX
    > 515E [6.3(3)]. The VPN works great except when the VPN
    > client is behind
    > another PIX or a Cisco router. If the VPN client behind a
    > PIX or a Cisco
    > router I can make the initial connect fine but I cannot pass
    > any traffic
    > (pings time out and protocols do not connect).
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Marcus J. Ranum: "[fw-wiz] Re: Flawed Surveys [was: VPN endpoints]"

    Relevant Pages

    • Local Lan Access not working
      ... Our head Office is using a Cisco Pix 515e Firewall behind a Cisco 827 ... One of our Directors connects into the company LAN from his home LAN ... using his company laptop and the VPN client. ...
      (comp.dcom.sys.cisco)
    • [fw-wiz] Cisco VPN Client Behind a Cisco PIX or Router
      ... I have configured a Cisco VPN Client to connect to a Cisco PIX ... isakmp policy 10 authentication pre-share ...
      (Firewall-Wizards)
    • [fw-wiz] Cisco PiX 501 running 6.2 - Defying me for no reason
      ... Well, after researching, configuring, reconfiguring, and just a bit ... the vpn client through the SecureWay firewall. ... The PiX is outside the firewall, on its own line/lines (explained in a ... the vpn eventually) can access the internet fine. ...
      (Firewall-Wizards)
    • RE: [fw-wiz] Pix 501 & 506 PixOS 7.0 compatability
      ... The info I got from a Cisco Security SE is that the 501 and 506 will support ... >>I am trying to configure a cisco pix as a vpn endpoint for the cisco ... >independent of anything the PIX or VPN client do. ...
      (Firewall-Wizards)
    • Re: Cisco PIX501 and incoming VPN from laptop via client software? Possible?
      ... Get PIX 501 with 3DES License for Firewall, ... get CISCO SECURE VPN CLIENT 3.5 ... > If I buy a Cisco PIX 501 to protect my home network, ... > kind of VPN client software on the laptop? ...
      (comp.security.firewalls)