Re: [fw-wiz] PIX in multiple IPsec roles



Dan Ritter wrote:
Is there a plausible way to convince a PIX to pass through an
IPsec tunnel to another device while simultaneously being an
endpoint for a different tunnel?

I have sites A, B, and C. Each has a PIX515E with tunnels to the
other two sites.

Now a vendor wants to establish a tunnel to a device inside
PIX A. I seem to be lacking the right keywords to search for
this.

-dsr-



I dont quite understand. this new tunnel you want to set up, will it go from the outside internet to something inside pixA or will it go from inside siteB or siteC to something inside siteA?

either way there should be no real problem that i can see, perhaps a smaller mtu if the latter case. if the former case you may have to map some services to the inside device.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: IPSec Transport or Tunnel Mode
    ... it is just a matter of selecting the option for tunnel mode and setting ... You need to set up 2 non-mirrored tunnel rules - one for ... each direction with the endpoint for that direction. ...
    (microsoft.public.security)
  • Re[2]: pf reply-to malfunction after r258468 (seems r258479)
    ... Is kernel rebuilding enuff? ... V> I have used a reply-to pf ruleset to sent all the traffic back via tunnel, ... V> it came via tunnel: ... this is not tunnel itself, because endpoint can ...
    (freebsd-current)
  • [fw-wiz] PIX in multiple IPsec roles
    ... Is there a plausible way to convince a PIX to pass through an ... IPsec tunnel to another device while simultaneously being an ... endpoint for a different tunnel? ...
    (Firewall-Wizards)
  • Re: BEFSR41 Linksys Router & VPN Setup
    ... > Does that mean that an XP machine can initiate the tunnel, ... > to have TWO routers providing an endpoint at each end? ...
    (comp.security.firewalls)
  • Re: Routing IPSEC packets?
    ... over the tunnels, I'd just use IPsec tunnel mode at ... IPsec is not integrated in anyway with IP routing. ...
    (freebsd-net)