Setting up a VPN between a Cisco 827H and a PIX

Posted on 2003-04-01
Medium Priority
Last Modified: 2010-03-19
I have a problem setting up a VPN between a Cisco 827H and a PIX.

Sorry for the long question but I think some details on the LAN/WAN setup might be useful.
Although I am OK on LAN and IP in general, setting up Cisco routers is a dark art to me :-)

Our customer has two LANs

Cisco Router (2600, I think)
ADSL Router
Cisco PIX
+8 Static IP Addresses
the routers and pix have their own real ip addresses from the static address pool, plus there are 2 unused real addresses.

Cisco 2600
Cisco 827H (ADSL)
+ 1 Static IP Address

Between the two offices they have a private 256K circuit, which is managed by the two 2600 routers. They do not use (or wish to use DHCP) as they want to limit web access by workstation (by blocking port 80 trafic to certain workstations).

I have been involved in setting up the 827H which is working fine, in the sense they have shared internet access from all the PCs. Someone (a cisco engineer) has been in and setup the 2600 so all internet trafic is sent through the 827H. This means that all the PCs have their 'gateway' set as the 2600's address. The 2600 address routes 192.168.2.x traffic through the 256k connection and internet trafic is sent to (the internal address of the 827H)

My only involvement has been the 827H, which we bought with the IPsec upgrade. That install OK as the VPN options are available on the web interface. I don't know if the is relevant, but when I ran the automatic configuration option for the ADSL side it set it to 'PPPoA' - Although, when it was setup, Internet access started working.

What I want to do is setup a VPN tunnel between the HQ PIX and the sub-office 827H. If I see a message 'VPN established' I will be happy :-) - how they use it is up to them. They want to use the Internet for the VPN as the 256K pipe is for other purposes.

On the 827H there are basically only 4 boxes:
Client or Network Extension Mode
IP Address

From reading the documentation, I believe I want network extension mode, so they will 'see' the WAN as a single LAN, (no NAT or PAT).

I have tried many options but it always fails. I have been told that the PIX needs to be setup to as VPN server, which is really my question.

How should it be setup?

Should I use one of the spare ip addresses? (it has a real address on its outside interface)
Will the 2600s get in the way?

I anyone can help with this I would be very grateful - It appears I can't get any help from Cisco

Question by:jon_harris
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 3
  • +2
LVL 79

Expert Comment

ID: 8245329
perhaps this link will help you out:

Expert Comment

ID: 8298726
jon_harris - Did you solve this, as I am trying to set up a simalar VPN myself and would appreciate a little advice if you have any


Expert Comment

ID: 8893343
How did you go with this one as I am in the same boat
WordPress Tutorial 1: Installation & Setup

WordPress is a very popular option for running your web site and can be used to get your content online quickly for the world to see. This guide will walk you through installing the WordPress server software and the initial setup process.

LVL 79

Expert Comment

ID: 8894090
I think you'll get a much better response if you post a new question of your own. This question seems to have been abandonded by jon_harris...
Be as detailed as you can with your own Q and we'll help you work it out.

Author Comment

ID: 8915789
Hi I am still around.

The simple answer is, No I haven't got it working and I am not sure what to do next.

The PIX has a very comprehensive GUI and appears reasonably easy to setup. The 827H does seem to have anything apart from a four box dialog.
The firewall capabilitities on the PIX are really nice to setup, but  the 827H has no setup for the Firewall, just an 'on' or 'off'!

The 827H is being marketed as a easy to setup and manage branch office router, it seems the only way to get it configured is to
telnet into it and do everything from the command line, the two things don't add up.

My client wants to block some workstation IP addresses  from using the web. This is a pretty standard requirement, the 827 GUI has no
way of doing anything - we paid for the Software feature pack to enable it do this.

I do not know of any other firewall that can't be setup to block port 80 on a particular LAN ip address in
more than about 30 seconds. For me the 827H was a complete waste of money. I wish I specified a low cost ADSL router and another
easy to setup firewall.

Whatever we tried, the 872H states that the VPN setup has failed. I have tried following some Cisco documentation but no luck. Every time I try to
set it up it loses the ability to route intenet trafic.

What I wanted was a clear do-this-do-that instructions for the PIX and then the 827H

I am completely stuck.I don't even know if  'easyVPN' (on the 827H)  the same VPN as on the PIX

The only solution I can come up with is to abandon the vpn on the 827, just using it as a router and get another PIX for the branch office.

Sorry to rant but cumulatively I have probably spent two days on this and I am no nearere a solution. I was recommended this setup
by the Cisco guys we bought if from and every one tells us it can be done, as soon as I ask some questions the meter starts running
and they won't help us.

Jon Harris

Expert Comment

ID: 8915824
You are going to have to get your hands dirty here Jon_Harris, the GUI just isn't going to do everything you want. You best unpack that nice blue cable from the cisco packing and start up a terminal client.

As for the config for the VPN I posted up something simalar recently and a very nice man posted a sample config:

I have issues with my ACL's somewhere, but the tunnels are created and teh VPN to some extent works

Author Comment

ID: 8916033
Hi fz2hqs

Many thanks for your response.

I have had a look at your thread will give that config a go.

I did n't mind setting up the vpn throught telnet, its just that I don't really know what I am doing. My understanding of VPN doesn't extend
much past the concept of an encrypted ip tunnel. Also I didn't want to want to break what was already working.

Also, what does to 'some extent' mean? :-)



Expert Comment

ID: 8916048
My tunnel is there I can see it from my PIX, however I have left somethign on the 827 that looks to be blocking traffic (the 827 is 115 miles away with no computer literate persoin near it!)

Keep us updated
LVL 79

Expert Comment

ID: 8916055
jon, what version OS on the PIX? Highly suggest upgrading to new 6.3(1) and PDM 3.01 GUI. The VPN wizard makes this a snap on the PIX end.

Author Comment

ID: 8918691
All I currently know is that it is a '506'. I am waiting for my client to get back to me on which IOS its running.

However, Its about 6 months old and it would have been the current release at that time.

Presumably, 6.3(1) is fairly new, so its unlikely they do have that version. I suspect that it is not a free upgrade either :(


LVL 79

Accepted Solution

lrmoore earned 2000 total points
ID: 8919174
It is a free upgrade if they have Smartnet maint.
It should work, regardless.

Expert Comment

ID: 9152773
This old question needs to be finalized -- accept an answer, split points, or get a refund.  For information on your options, please click here-> http:/help/closing.jsp#1 
Post your closing recommendations!  No comment means you don't care.
LVL 79

Expert Comment

ID: 9161818
RECOMMENDATION: Points awarded to: lrmoore

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses
Course of the Month12 days, 18 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question