How do I securely setup PIX 501 site to site VPN for client network management

Posted on 2006-04-19
Last Modified: 2013-12-03
Hello Experts,

I have a PIX 501 at my office.  The clients I do network managment for have PIX 501's as their edge device.

I would like to setup permanent site to site VPNs with them but I would like to do the following:

Allow - All traffic originating from my subnet to the client networks
Deny - All traffic originating from client subnets to other client subnets

Basically I do not want to be a Hub allowing spoke to spoke communications.

Can this be done easily?

Please provide detailed pix configuration commands to make this happen.

Thanks in advance!

Question by:jamie177
    LVL 32

    Accepted Solution


    Author Comment

    Thanks Rajesh,  I've setup the peer to peer tunnel before.  I want to setup peer to peer tunnels from my PIX to multiple client PIXes and ensure that the client networks cannot talk to each other.

    Is there anything special I need to do so far as access-lists?


    LVL 32

    Expert Comment

    No. you should be okay with the same set of configurations because your access-lists would be only opening up central to client1, central to client2 and so on. So client1 to client2 wouldn't be possible unless you configure it. Something like this;

    Say your internal is 10.10.10.x, client1 is 10.10.20.x, client2 is 10.10.30.x

    access-list 100 permit ip 10.10.10.x mask 10.10.20.x mask
    access-list 100 permit ip 10.10.10.x mask 10.10.30.x mask

    so client1 and client2 won't talk to each other.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    6 Surprising Benefits of Threat Intelligence

    All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

    How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
    Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now