?
Solved

VPN with PIX 506E as hub and pix 501 as clients

Posted on 2006-03-22
1
Medium Priority
?
229 Views
Last Modified: 2010-04-12
Am new to setting up VPN between pix-to-pix. I have a Pix 506E running PIX Firewall Version 6.3(5)and we want to use it at the HQ with five PIX 501 running IOS version 6.3 in the branches. I need help on how to get the VPN set up, any resouces I can use or any configuration examples. I intend to set them up with  static IPSEC with NAT. Any clues and examples will be appreciated.
0
Comment
Question by:ackim
1 Comment
 
LVL 20

Accepted Solution

by:
calvinetter earned 2000 total points
ID: 16265073
 See the following example for a "hub-and-spoke" site-to-site VPN:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080093bd3.shtml

  If you want the branches to be able to talk to each other as well as HQ, you'll need to instead setup a "fully-meshed" layout, since PIX 6.x doesn't support spokes talking to each other in a "hub-and-spoke" arrangement:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800a2cce.shtml

   Note that the fully-meshed example uses PIXes running old 6.1 code, but otherwise it's a good example.  The only addition I'd make to *all* your PIX configs (since they're all v6.3, & regardless of which scenario you go with) is to add:  
  isakmp nat-traversal

PIX 7.x supports spoke-to-spoke communication, but it currently only runs on PIX 515/515e or above.

cheers
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Using Windows 2008 RRAS, I was able to successfully VPN into the network, but I was having problems restricting my test user from accessing certain things on the network.  I used Google in order to try to find out how to stop people from accessing c…
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses
Course of the Month15 days, 15 hours left to enroll

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question