Cisco Pix IPSec VPN

Posted on 2003-03-18
Medium Priority
Last Modified: 2010-08-05

I have this problem I hope someone is able to answer me.

Over here on the company we use a router and a pix firewall the setup is as follows:

|| INTERNET ||----|| Router ||----|| PIX ||----|| LAN ||

Everything is well. We have internet from the inside -> out. Our webserver is reachable from the outside, so is our mailserver.

Also are our homeworkers able to establish a connection to the pix (Cisco Secure Firewall Pix 515 Software Version 6.2 PDM version 2.11) using an IPSec tunnel. They all use Cisco Secure VPN Dialer 3.x
I have currently activated splittunneling but for safety I want to turn this off and make all clients access the internet through the corporate network.

Is there anyone that is able to provide me with a config example of how to achieve this. I am not posting my running config because I don't see the advantage of that. I just need a example config.

Ofcourse any help would be appreciated. :D
Question by:MaartenS
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Author Comment

ID: 8164874
Thanx mate but I allready tried that one...
LVL 79

Expert Comment

ID: 8175402
You can disable split-tunneling just by removing the vpn group split-tunnel line in the config.
Now the real problem is that you want the users to still be able to browse the internet while connected to the PIX, but using your corporate Internet connection, with all the controls and restrictions as for anyone within the LAN? Is this your only firewall?
The issue is that a PIX will not re-direct a packet back out the same interface that it came in on. Example,
My VPN client want's to go to www.cisco.com. That request gets resolved to the proper external IP address, then the packet comes into the PIX from the outside, with a destination point that is also outside, so it requires a re-direct.

If  you have another firewall for outgoing, then you run into a routing issue.

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.


Author Comment

ID: 8177072
No we have 1 internet connex with 1 router and 1 pix.

As said the clients come in on the same pix that all the internet traffic has to go out through...

So your telling me that is not possible?
LVL 79

Accepted Solution

lrmoore earned 1000 total points
ID: 8177175
To my knowledge (and vast PIX experience), it is not possible on the PIX.
You could use a VPN concentrator to terminate the VPN, and route the traffic back out through the PIX. Sort of like this:
            / -VPN-----|
Router--|               |---LAN---
            \ -PIX-------|

Author Comment

ID: 8179303
Thanx I will look into it...

Featured Post

Turn your laptop into a mobile console!

The CV211 Laptop USB Console Adapter provides a direct Laptop-to-Computer connection for fast and easy remote desktop access with no software to install.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Overview Often, we set up VPN appliances where the connected clients are on a separate subnet and the company will have alternate internet connections and do not use this particular device as the gateway for certain servers or clients. In this case…
Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month12 days, 15 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question