3000 concentrator question

Posted on 2004-11-15
Last Modified: 2013-11-16
are network topology is as follows

perm router-->pix 506-->3600 router-->local lan

We have a 3000 concentrator in between the perm and pix 506 that is setup for users for vpn.

the pix is setup for pix to pix vpn with a colo.

Users who authenticate in thru the vpn want to access the subnet on the colo. I tried adding a static route for the colo subnet on the 3000 but it fails. cccccccan it be done?
Question by:cogit
    LVL 36

    Expert Comment

    Hi cogit,
    Please explain where the colo network connects in your diagram above.

    Author Comment

    Here is the topology

    Perm router so: 75.X.X.X
    E0: 76.X.X.X
    3000 concentrator: public:76.x.x.x
    LOCAl pool (on the concentrator)
    Pix 506. outside 76.x.x.x
    Router 3600
    fa/01: (local network)

    THE PIX 506 setup with PIX to PIX VPN to connect to the colo 10.20.2.x network

    When inside the internal network 10.12.0.x we of course can connect to the colo network.  

    On the 3000 there is a ip routing tab where you can place static routes.
    LVL 36

    Accepted Solution

    Yes it should be possible to get this working.

    On the concentrator make sure you have the following route defined:- mask gateway

    On the 506 make sure the following route is defined :- mask gateway

    At the co-lo end I assume everything goes via the PIX?

    On the PIX-PIX VPN configuration at both ends  you will need to check the access-list which defines which traffic is to be sent across the VPN and make sure it includes traffic from

    Author Comment

    hear is what is on the pix
    route outside 76.x.x.x
    route inside 1
    route inside 1
    route inside 1

    on the pix 506

    access-list nonat permit ip
    access-list nonat permit ip

    access-list IBM-link-acl permit ip
    access-list IBM-link-acl permit ip

    On the other pix I should have has thats says (something to this effect ?)
    access-list xxx permit ip
    access-list xxx permit ip

    Author Comment

    resolved it

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
    If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now