RE: [fw-wiz] Pix VPN endpoint and split-tunnel

From: Paul Melson (
Date: 10/14/05

  • Next message: Josh Welch: "Re: [fw-wiz] Pix VPN endpoint and split-tunnel"
    To: "'Josh Welch'" <>
    Date: Fri, 14 Oct 2005 09:24:12 -0400

    -----Original Message-----
    > I've recently been playing with 7.0(2) on a 515E previously running
    6.3(3). It requires
    > a memory upgrade, but you can upgrade a 5xx series PIX to version 7.x of
    the PIX OS.

    For what it's worth, PIX OS v7 and the ASA v7 software are not the same
    animal, and the new PIX code still doesn't include RIPv2 support or split
    horizon. But after doing some digging, it looks like PIX OS v7 might solve
    Chris' problem after all:

    "Improved Support for Non-Split Tunneling Remote-Access VPN Environments:
    Enables remote-access VPN connections to be terminated on the outside
    interface of a Cisco PIX Security Appliance, allowing Internet-destined
    traffic from remote-access user VPN tunnels to leave through the same
    interface it arrived at (after firewall rules, URL filtering policies, and
    other security checks have been optionally applied)"

    But it's still going to cost them the money to upgrade their PIX to 128MB of
    RAM. That's going to be a lot cheaper than an ASA or VPN3K though.


    firewall-wizards mailing list

  • Next message: Josh Welch: "Re: [fw-wiz] Pix VPN endpoint and split-tunnel"

    Relevant Pages

    • Re: Dual gateway configuration on ASA 5520
      ... have a default gateway on interface outside2, route ... PIX / ASA does not have source routing. ... The usual way of handling this sort of thing on PIX / ASA ... route to 10.3.x.x was through the outside2 interface so it would ...
    • Re: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls
      ... I just spoke with a Cisco sales rep about this. ... > Cisco is marketing the ASA 5500 appliances as PIX, VPN Concentrator, Secure ... > least out of scope features, ...
    • Re: Looking to replace a Netscreen-100
      ... secondary ip addresses on its trusted interface, ... the sense that the PIX will only *itself* respond to one IP ... a "router on a stick" between subnets. ... The ASA and PIX run exactly the same binary images ...
    • Re: VPN from my PC to work through ASA
      ... I am trying to connect remotely via VPN to this Cisco Pix, however, I ... think the ASA is not allowing this. ...
    • Difference between PIX and ASA
      ... can someone explain me the differnces between a PIX and an ASA, especial a PIX 515E/R and an ASA 5510 plus. ... I have the problem to combine and expand our PIX based network with a watchguard and soho-router based network. ... In the first step i will replace the 2port Watchguard on the other mainoffice with a PIX or ASA with minimal 3 NICs to implement among other things a DMZ, site-to-site VPN and the possibility for the use of the Cisco VPN-Client. ...