• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 388
  • Last Modified:

PIX-to-PIX IPSEC in addition to Cisco Client VPN

Hi all,

We already have our PIX firewall configured to accept connection from Cisco Client VPN; we have a client that would like to establish a PIX-to-PIX VPN session with our office.
Is it possible to have both configurations (i.e. client vpn and lan-to-lan vpn) running on the same firewall?

Thank you
0
tshi5791
Asked:
tshi5791
1 Solution
 
Seamless-ITCommented:
Yes, here is an example of the config. It's just the crypto stuff so you would need to add your ACL.

Map 20 is the site to site and 50 is the dynamic. Make sure that you put no-xauth no-config mode after the isakmp key.

crypto ipsec transform-set myset esp-des esp-md5-hmac                                                    
crypto dynamic-map dynmap 50 set transform-set myset                                                    
crypto map mymap 20 ipsec-isakmp                                
crypto map mymap 20 match address xxx                                      
crypto map mymap 20 set peer x.x.x.x                                      
crypto map mymap 20 set transform-set myset                                          
crypto map mymap 50 ipsec-isakmp dynamic dynmap                                              
crypto map mymap interface outside                                  
isakmp enable outside                    
isakmp key ******** address x.x.x.x netmask x.x.x.x no-xauth no-config mode
isakmp identity address
isakmp nat-traversal 20
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
vpngroup xxx address-pool vpnips
vpngroup xxx dns-server x.x.x.x
vpngroup xxx default-domain HealthEffects.org
vpngroup xxx split-tunnel xxx
vpngroup xxx idle-time 1800
vpngroup xxx password ********

-Adam
0
 
tshi5791Author Commented:
Thank you for the info, I was able to add this to our current config and have it to work.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now