[fw-wiz] PIX to PIX VPN from within a private network.



Hello,

I have a PIX at home and would like to connect via site to site VPN
to the PIX at work which I also maintain.

The problem I think I may run into is I have a private network between the internet router and my internal home PIX. The segment between the internet router and the internal PIX is 10.0.0.0/24, the outside interface of the PIX is numbered 10.0.0.1.


I'll try my hand at drawing this out:


WORK: INTERNAL-NET(10.31.0.0/16) >> PIX(NAT) >> INTERNET

HOME: INTERNAL-NET(216.138.246.208/27) >>
(inside int 216.138.246.209)PIX(outside int 10.0.0.2) >>
(10.0.0.1)Cisco827dsl(216.138.247.130) >> INTERNET

or in simple:

INTERNAL-HOME-NETW(internet routable) >> ROUTER >> PIX >> INTERNET


Can I set up a site to site vpn, apply the config to the external interface of the pix(10.0.0.1) and be able to connect work's PIX without issues (due to the fact 10.0.0.1 would not be routeable on the internet)?

I hope I'm being clear in what I'm after. I envision the PIX at work trying to connect back to 10.0.0.1.



thanks in advance,

greg



_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • RE: [fw-wiz] PIX to PIX VPN from within a private network.
    ... Your best bet would be to have your ISP configure your internet router ... I have a PIX at home and would like to connect via site to site VPN ...
    (Firewall-Wizards)
  • Re: Site to Site VPN with PIX 515e and Linksys RV082
    ... >I've been trying to get a site to site vpn up and running between 2 sites, ... I'd be inclined to investigate the ARP situation first. ... You are probably using nat 0 access-list on the PIX: ...
    (comp.dcom.sys.cisco)
  • PIX 7.x VPN Client and site to site VPNs
    ... I read that version 7.x allows the PIX to route back over the same ... PIX connected to Site A via site to site VPN ... Client PC: connects to Site A from home internet connection via Cisco ...
    (comp.dcom.sys.cisco)
  • Re: Cisco Pix 501 Very Strange issues ! Newbie needs help !!
    ... I have a cisco pix 501 using 3des site to site VPN as well as Standard ... mins then that drops. ... Have you added any more devices, even network printers in ...
    (comp.dcom.sys.cisco)
  • Re: PIX501 Site to Site ICMP Problem
    ... >site to site VPN. ... This agrees with the client side address for the split tunnel. ... This ACL is read as 172.31.40.x on the PIX side and a few other things ...
    (comp.dcom.sys.cisco)