Advertisement

03.15.2007 at 10:50AM PDT, ID: 22452170 | Points: 500
[x]
Attachment Details

Site to Sites PIX, VPN Client access from behind

Asked by iaintarr in IPSec Security Protocol, Virtual Private Networking (VPN), Network Software Firewalls

Tags: pix, vpn, client, site, access

I have three sites

Hub Site - PIX 506
Satellite 1 - PIX 501 (site A)
Satellite 2 - PIX 501 (site B and site C)

They are all configured in site to site configuration with the main Hub site.

the satellite sites have 1 static IP each
the hub has 2 static ip's.

The hub site uses one static IP for the site to site PIX config.

The A site has the static public IP terminating on the pix interface.

The B site has the IP terminating on the pix interface.

The C site has the 500 udp forwarded from a adsl router to an internal IP which terminates on the pix inside.

All site to sites work perfectly.

my issue  is with accessing (vpn)  the main hub from behind site B's and site C's pix with the cisco vpn client
another issue is connecting from behind sites C's ADSL router.
The connection attempts are made, but "terminated locally by the client"

Nat traversal is on.

Now as i see it there is some complication with these vpn clients accessing the main pix from the same ip as the site to site is configured with.

any help would be appreciated.






Start Free Trial
 
Loading Advertisement...
 
[+][-]03.15.2007 at 11:06AM PDT, ID: 18729090

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.15.2007 at 11:15AM PDT, ID: 18729149

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.04.2008 at 07:12AM PDT, ID: 22387534

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32