Re: Pix and VPN 3030 traffic routing / redirection
From: Eric Chamberlain (telogix@hotmail.com)Date: 03/27/02
- Next message: Brett: "SnapGear???"
- Previous message: Charles Newman: "Re: port 1214"
- In reply to: Paul B.: "Pix and VPN 3030 traffic routing / redirection"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Eric Chamberlain" <telogix@hotmail.com> Date: Wed, 27 Mar 2002 05:00:20 GMT
"Paul B." <pfb71@hotmail.com> wrote in message
news:3c9f728c.260449236@news.qwest.net...
> Currently I have a Pix 515 serving as both a firewall and a VPN
> termination point for both site-to-site and VPN software client-based
> VPN sessions. The Pix has three interfaces (outside, dmz, and inside)
> on three networks. I've recently purchased a Cisco VPN 3030 that I
> plan to put in parallel with the Pix (see
>
http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/3_5/getting/gs1u
nd.htm
> for a nearly perfect diagram of what I'm planning).
>
> Our goal is to move all VPN traffic from the Pix to the new 3030. My
> question has to do with routing (or, perhaps, redirection). First,
> I'll put out some basic info:
>
> Pix inside interface network: 192.168.10.0 (Default gateway for
> clients behind firewall)
> Pix dmz interface network: 192.168.20
> Pix outside interface network: 192.168.30.0
> Pix VPN software client pool: 10.0.0.0
>
> VPN 3030 inside interface network: 192.168.10.0
> VPN 3030 outside interface network: 192.168.30.0
> VPN 3030 VPN software client pool: 10.10.0.0
>
> Sample remote site network for site-to-site VPN: 172.16.3.0
>
> If a packet from the 192.168.10.0 network is bound for 172.16.3.0 it's
> going to go directly to its DG, the inside interface of the Pix.
> Similarly, if a packet from 192.168.10.0 is bound for 10.10.0.0 (i.e.
> a return to a VPN software client request) it too will go directly to
> the inside interface of the Pix. My question is how do I redirect that
> traffic from the Pix to the inside interface of the 3030? I suspect I
> may need to use a combination of some route statements and icmp
> redirection on the Pix to accomplish this but I'm at a loss. The only
> other alternative I can think of is to put a router ($$$) behind the
> inside interface of the Pix and handle it that way. Given budgetary
> constraints I can't really do that right now.
>
The PIX is a firewall, not a router, if will not redirect traffic out the
same interface it came in on. You will need a router between the inside
network and the PIX/VPN Concentrator. The router will then route the
traffic to the apropriate device.
-- -- Eric Chamberlain CISSP, CCNA, CCDA, MCSE, CCA
- Next message: Brett: "SnapGear???"
- Previous message: Charles Newman: "Re: port 1214"
- In reply to: Paul B.: "Pix and VPN 3030 traffic routing / redirection"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|