Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Complex VPN Config - VPN to a network not on the VPN connected device (behind a second firewall)

Posted on 2006-06-13
Medium Priority
Last Modified: 2013-11-16
I have 6 internal 192.168 networks behind a firewall. I need VPN access to these networks but I can't make the firewall itself the VPN endpoint.

I have the following setup.

I have a VPN in place between my office (Cisco PIX506E) and a Cisco 2811 router. I then need to get from the router to the 192.168 networks behind a firewall which I don't directly manage.

+-------------------+                +-------------------+             +---------------------+                 +--------
| PIX506E            |                | 2811                 |             | Firewall              |                  +--------
|Ins |-------------|Ins    |-----------|Ins|--------------+--------
|Out    |                |Out   |              |Out     |                 +--------
+--------------------+               +-------------------+              +--------------------+                 +--------

I have ny VPN setup between two endpoints - and

What static route statements do I need now, and where do I need them, to ensure that I get from the network behind my PIx through to the 192.168.0-5.0/24 networks behind the firewall and back again ? I have tried a number of different configs and haven't yet been able to get this to work.

Also, in my crypto access lists for the traffic to be protected by the VPN, I assume I need to add an entry for the destination 192.168.0-5.0/24 networks, as well as entries for the inside networks on the PIX and 2811.

Any help would be greatly appreciated.

Question by:ccfcfc
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 2
  • +1

Expert Comment

ID: 16895583
Well one way or the other, you will have to make changes to the Firewall that you don't manage to get this setup to work. What is the default gateway of the Firewall ( Is it the 2811 ( And what brand of firewall is


Author Comment

ID: 16897206
Firewall is proprietary, provided by the ISP. The 2811 is not the gateway for this firewall.

The setup was originally a standard one. For reasons which I won't go into we can't use the ISP firewall for VPN connections. These will all need to go from the PIX to the 2811, and then on to the ISP firewall, and then reversed to go the other way.

The gateway for the 2811 is

The ISP firewall will pass all traffic from 192.168.0-5.0/24 back out to the internet, except for traffic which has been defined as being destined for the VPN, i.e. traffic from the PIX, which will be passed to the 2811 instead of straight back out to the Net.


Author Comment

ID: 16897214
I forgot to say, although we have no direct control over the ISP firewall we can request whatever changes are needed to make this configuration work.

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

LVL 28

Accepted Solution

mikebernhardt earned 672 total points
ID: 16897478
The static routes you should need for this is
1. On the 2811, a default route out to the internet and also a route for with a next hop of
2. On the PIX a default route and also routes for with a next hop of

Since the firewall is dealing with decrypted traffic, it will need to pass all traffic between the private networks on either end- from to the others and back. Same for the crypto maps. It doesn't matter what's connected, what matters is the source and destination networks.

If I'm missing something I'm sure someone else will add to this.
LVL 11

Assisted Solution

prueconsulting earned 664 total points
ID: 16897484
Assumption of course is that the ISP firewall does not perform NAT'ing?

LVL 28

Expert Comment

ID: 16897506
Ummm...good point. If those subnets are NATted then you need to substitute the public addresses.

Assisted Solution

stressedout2004 earned 664 total points
ID: 16897723
Here's what you need:

PIX 506e:

a) Modify the NAT 0 and Crypto match address access-list so that it includes traffic to to 4.0/24 from
b) As far as routing is concern, there's no need for any explicit static routes to the remote network as long as this PIX
has a default gateway going out to the internet. Of course I am assuming that the PIX 506e is connected to the internet and is on an entirely different location from the 2811.

a) Modify the crypto match address to include traffic to from to 4.0/24.
b) A static route for to 4.0 pointing back to the

Firewall controlled by ISP:

a) You need a static route for pointing back to
b) If your ISP is doing NAT (which is most likely the case, otherwise won't get internet access),
asked them to make a NAT exception rule such that when the network to 4.0/24 communicates with they won't be NATted.


Author Comment

ID: 16902764
I have amended my configs with the changes above that hadn't been made already.

When I now try to map a drive from a PC on, behind my PIX, to at the other end it seems to almost work. If I go to mapped drives in Explorer I can see the drive listed, but it seems to lock up explorer and I can't actually access the drive. Any ideas on how I can try to diagnose what might be happening ?

Also, how can I configure a Cisco VPN Client to get to the 192.168.0-4.0 networks ? If I have a VPN connection to, I assume that the routing statements already in place as detailed above will get the traffic through to the 192.168.0-4.0 destination, but how does my PC where I'm running the client know to send that traffic down the VPN tunnel instead of straight out to the Net through the normal route ? I don't have an access-list at the VPN Clinet end that will capture that traffic ?

Thanks for all the help so far.

Author Comment

ID: 16903515
Update -

I mapped a drive from to a PC behind my PIX, on, aand left it running. When I went back a few minutes later the drive mapping was listed in the Disconnect Network Drive under Explorer Tools on, and was also listed as a drive under My Computer.

However, when I click on it to access it Explorer seems to hang. It seems as though traffic is getting across the VPN tunnel but it's running extremely slowly. Any ideas on how I can diagnose where the problem could be ?
LVL 28

Expert Comment

ID: 16904218
>how does my PC where I'm running the client know to send that traffic down the VPN tunnel
The PC has to have the correct route, which is called split tunneling. You can do a route add for now just to test. Most VPN servers can supply the routes to the client, you should look at how to configure it on the 2811 (I don't know). Maybe it's already doing it- try netstat -rn on your PC when the vpn is up and when it's down.

It's possible that if you get that fixed data will flow better too. Let's get that done first. Also make sure that the firewalls on both sides are permitting all IP between the subnets- at least until everything is working and you know what you need.
LVL 28

Expert Comment

ID: 17083928
I'd suggest splitting the points between me and stressedout2004...

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question