Re: [fw-wiz] PIX to PIX VPN from within a private network.



Hi, all!

On Mon, Mar 13, 2006 at 06:02:55PM -0500, Greg wrote:

I have a PIX at home and would like to connect via site to site VPN
to the PIX at work which I also maintain.

The problem I think I may run into is I have a private network between
the internet router and my internal home PIX. The segment between the
internet router and the internal PIX is 10.0.0.0/24, the outside
interface of the PIX is numbered 10.0.0.1.

AFAIK PIXen with current software (6.3.something) will do NAT
traversal for IPSec just fine (using UDP port 4500).

You will have to make sure that your Internet router at home
permits and NATs bidirectional traffic on UDP ports 500 (IKE)
and 4500 (IPSec) when the session is initiated from the inside.
This should be the case for a standard "permit and NAT anything
inside -> outside" configuration that is most often used
in SOHO setups.

Then it should "just work".

Of course you configure the external IP address of your
SOHO router as the peer on the company's PIX. Not 10.0.0.1.

And for most simple SOHO devices in standard configuration you
will need to initiate the IKE and IPSec SA from your side.
If you want both PIXen to be able to start talking to each other
you need to define incoming PAT for ports 500 and 4500 on
your SOHO router.

HTH,
Patrick
--
punkt.de GmbH Internet - Dienstleistungen - Beratung
Vorholzstr. 25 Tel. 0721 9109 -0 Fax: -100
76137 Karlsruhe http://punkt.de
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • RE: [fw-wiz] PIX to PIX VPN from within a private network.
    ... Your best bet would be to have your ISP configure your internet router ... I have a PIX at home and would like to connect via site to site VPN ...
    (Firewall-Wizards)
  • Re: MRTG (SNMP) through a PIX
    ... I would suspect that you have permitted the inside IP address to poll, but the PIX is translating it to a public IP address. ... map your graphing server to an open IP address and allow this in your list. ... from our Internet router, ... When I try to connect to the router from the MRTG PC, ...
    (comp.dcom.sys.cisco)
  • Re: PIX 515E Configuration Help...
    ... Is there a specific ethernet port for the internet router? ... It is in ethernet 3 of the PIX. ... refering to the PIX interfaces when i say e0,e1, and e3. ...
    (comp.dcom.sys.cisco)