[fw-wiz] l2tp/Ipsec and pix

From: Jean Caron (caronj_at_norac.net)
Date: 01/14/05

  • Next message: Wes Noonan: "[fw-wiz] Per application port DMZ segments?"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 14 Jan 2005 10:47:54 -0500
    
    

    Hi,

    Is it possible to have a l2tp/ipsec tunnel go through a pix firewall?

    I have a win client establishing a l2tp/ipsec tunnel to a pix. Works fine.
    But now I need to throw another pix in to protect the client. So I'm trying
    to have the tunnel go *through* this second pix.

    The client address needs to be NATed on the outside of this second pix.

    Here's part of the "debug crypto isakmp" output;

    ISAKMP (0): atts not acceptable. Next payload is 0
    ISAKMP (0): SA not acceptable!
    ISAKMP (0): sending NOTIFY message 14 protocol 0

    Again, if I remove the second pix, use it's outside address on my win client
    and adjust the policy's endpoints accordingly, the tunnel comes up just
    fine.

    Jean
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Wes Noonan: "[fw-wiz] Per application port DMZ segments?"

    Relevant Pages

    • Loss of VPN Access Using Pix 501
      ... I have a client who is using a Pix 501, ... Establish secure connection using Ethernet ... Peer supports XAUTH ...
      (comp.dcom.sys.cisco)
    • Re: PIX site-to-site VPN
      ... PIX 1: ... access-list acl_to_city2 ip host 10.y.y.1 host 222.222.222.222 ... isakmp identity hostname ... crypto map map_to_city2 100 set peer 222.222.222.222 ...
      (comp.dcom.sys.cisco)
    • RE: [fw-wiz] Cisco PiX 501 running 6.2 - Defying me for no reason
      ... >>connected with the PiX between it). ... > assign static IPs, so when I transfered the static to the firewall, the ... I cannot ping names, such as ... server and have it issue an IP and DNS server to your client PC? ...
      (Firewall-Wizards)
    • Re: INTERNET ACCESS AND CISCO PIX FIREWALL
      ... 2 client PCs are in another room and I would prefer to give them ... replace the Cisco Pix Firewall with a wireless firewall router? ... Microsoft MVP - Windows Server Directory Services ...
      (microsoft.public.windows.server.networking)
    • Re: SBS VPN vs Router VPN
      ... I'm using one NIC on the server, and the pix 506e only has one internet ... The higher level pix models can take two. ... Is your router or SBS doing DHCP? ... Configure the PIX for remote vpn access, then install the client on the ...
      (microsoft.public.windows.server.sbs)