[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Cisco VPN Client terminating on my inside interface, can I allow access to my DMZ?

Posted on 2004-11-12
1
Medium Priority
?
243 Views
Last Modified: 2013-11-16
Hello!  I recently got my Cisco VPN client working to my Pix520 and it's working like a champ!  However, I want to be able for my employees to access our DMZ as well just as if they were sitting at their desk at work.  I've tired numerous router statments but I'm wondering if I'm going over to many hops on my firewall?  Anyone have any thoughts?

I can browse the internal network fine, but simply can access or ping my DMZ.  I believe it's a too many hops in and out of the firewall, but thought I would ask here to be sure.  

Thanks in advance!
0
Comment
Question by:TJanousek
1 Comment
 
LVL 5

Accepted Solution

by:
martap earned 500 total points
ID: 12570967

Were is your DMZ? On the same PIX? If so just do:

access-list nonat permit ip x.x.x.x 255.255.255.0 y.y.y.y 255.255.255.0
nat (dmz) 0 access-list nonat

x.x.x.x = DMZ range
y.y.y.y = VPN client range

If you have use split tunneling you will have to add the DMZ range to that access-list too.

good luck...

P.S. To better asist you it's always a good idea to post your config.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question