Advertisement

07.25.2008 at 02:42AM PDT, ID: 23594945 | Points: 250
[x]
Attachment Details

Cisco VPN Static routing routing and port mapping issue

Asked by afamm in Cisco PIX Firewall, Network Routers, Virtual Private Networking (VPN)

Tags: , ,

Hello,
I have 3 networks A ,B And C  the main office network is in network B and i have the Pix firewall in Network B. Also in network B, i have 2 cisco routers within network B with Lan interface ip on the same network sawith network B and this 2 cisco routers is used to send traffic to Network C.

Ip address of A is : 213.226.X.X
Ip address of B:(the firewall is 87.252.X.X with Lan interface of 192.168.0.1)and the lan interface of the 2 cisco routers are 192.168.0.6 and 192.168.0.7.
Ip address of Network C is :160.40.X.X.
On the cisco router(87.252.X.77), I want to create a static route to C (160.40.X.X.) through 192.168.0.6 and 192.168.0.7(the 2 cisco routers).
I also want to provide access from A (213.226.X.X) through the firewall through 192.168.0.6 and 192.168.0.7 to C (160.40.X.X.) using port 23515 and 23526.

I think my command should be as below.
access-list smtp permit tcp any host 87.252.X.X eq 23526 and access-list smtp permit tcp any host 87.252.X.X eq 23515
i am also thinking of doing a static command like below.
static (inside,outside) 87.252.X.X 192.168.0.6 netmask 255.255.255.255 0 0 and also
static (inside,outside) 87.252.X.X 192.168.0.7 netmask 255.255.255.255 0 0
How do i allow static route from  A  (213.226.X.X) to pass through the firewall and through either to the 2 cisco routers to the C (160.40.X.X)

Find below the config of the firewall if it will help.


access-list smtp permit icmp any any echo-reply
access-list smtp permit icmp any any time-exceeded
access-list smtp permit icmp any any unreachable
access-list smtp permit tcp any host 87.252.X.76 eq smtp

access-list 102 permit ip 192.168.0.0 255.255.255.0 10.0.0.0 255.255.255.0
access-list outside_cryptomap_dyn_10 permit ip any 10.0.0.0 255.255.255.224
pager lines 24
logging monitor debugging
icmp permit any inside
mtu outside 1500
mtu inside 1500
ip address outside 87.252.X.77 255.255.255.248
ip address inside 192.168.0.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
ip local pool ippool 10.0.0.10-10.0.0.25
pdm history enable
arp timeout 14400
global (outside) 1 interface
global (outside) 1 87.252.X.78
nat (inside) 0 access-list 102
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) 87.252.X.76 192.168.0.5 netmask 255.255.255.255 0 0
access-group smtp in interface outside
route outside 0.0.0.0 0.0.0.0 87.252.X.78 1

Your suggestion will realy help. I also do have a set of free IP address thet i can use in the routing. Should i use a differet IP address for the access list or use the PIX IP address.

Regards.


Start Free Trial
[+][-]07.25.2008 at 04:37PM PDT, ID: 22092991

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.27.2008 at 11:27PM PDT, ID: 22100985

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.28.2008 at 05:49AM PDT, ID: 22102524

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.29.2008 at 09:53AM PDT, ID: 22113319

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.29.2008 at 10:08AM PDT, ID: 22113449

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.29.2008 at 10:31AM PDT, ID: 22113641

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.29.2008 at 10:41AM PDT, ID: 22113732

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.30.2008 at 03:20AM PDT, ID: 22118950

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.30.2008 at 06:23AM PDT, ID: 22120106

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.01.2008 at 01:52AM PDT, ID: 22136450

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.05.2008 at 10:41PM PDT, ID: 22167360

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.11.2008 at 09:28AM PDT, ID: 22205805

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628