Pix 515 Setup Help Needed

Posted on 2006-04-04
Last Modified: 2013-11-16
We have a Pix 515 Firewall.  We want to be able to set it up for remote vpn access using ipsec.  

Outside IP address is X.X.X.1
Inside IP address is 192.168.1.X

These are the things that I know.  I need some help with the rest of the setup and I do not have access to sample configs on Cisco.

Any help would be helpful
Question by:melron12
    LVL 25

    Accepted Solution

    Here's a start.  Also, change your vpn pool, its a public IP range.  
    I'll use:
    ip pool local vpnpool mask
    check syntax for above command to make sure
    then add
    access-list nonat permit ip
    access-list splitvpn permit ip
    nat (inside) 0 access-list nonat
    sysopt connection permit-ipsec
    isakmp enable outside
    isakmp policy 10 authen pre-share
    isakmp policy 10 encrypt 3des
    isakmp policy 10 hash md5
    isakmp policy 10 group 2
    crypto ipsec transform-set esp-3des-md5 esp-3des esp-md5-hmac
    crypto dynamic-map dynmap 10 set transform-set esp-3des-md5
    crypto map outsidemap 10 ipsec-isakmp dynamic dynmap
    crypto map outsidemap interface outside

    now are you running version 6.X or 7.X - there are other options but these should get you going
    for 6.X
    vpngroup <username> password <password>
    vpngroup <username> split-tunnel splitvpn
    vpngroup <username> address-pool vpnpool

    for 7.x
    have to get back to you as you have to create a group policy and then create a tunnel-group, this is because vpngroup is deprecated in 7.X

    you might want to double check the syntax but this should give you a good start

    Author Comment

    I get connected via vpn....I recieve ip address....and I am not able to browse the inside network
    LVL 25

    Expert Comment

    you did do the split-tunnel right?

    can you post the config file you have (sanitized of course)

    Author Comment

    I can not browse the internal network.... but I can not browse the internet on my remote computer.


    LVL 25

    Expert Comment

    please post your config so I can see what is wrong.

    thank you

    Author Comment


    I can browse the internal network.... but I can not browse the internet on my remote computer
    LVL 25

    Expert Comment

    okay, then I"ll need two things. first your pix config and second on the remote machine, after you setup the vpn what does the route table say
    in windows
    route print

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    Join & Write a Comment

    How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
    When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
    Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    23 Experts available now in Live!

    Get 1:1 Help Now