?
Solved

Cisco Pix to Pix VPN with 4.x VPN Client

Posted on 2006-06-21
3
Medium Priority
?
333 Views
Last Modified: 2010-03-19
I have two offices, A & B that are connected through a Pix-to-Pix VPN.  All traffic runs great through this.  I have VPN client access at each of these Pixes as well, can connect to either A or B and see the local network.  I need to provide access for users to connect with a client VPN to office A and be able to access resources in office B.  When a user is connected the the VPN, they must not have access to the Internet.  Any insight on this would be great.

Thanks


VPN CLIENT ------ Office A ---------- Office B --------- VPN CLIENT
0
Comment
Question by:netspheretech
  • 2
3 Comments
 
LVL 15

Expert Comment

by:Joseph Hornsey
ID: 16957166
I had to set this up recently.

Here's basically what you do.

First, set up your PIX-to-PIX VPN tunnel (if it isn't already set up - sounds like it is).  If it isn't, then a great doc is here:
http://www.cisco.com/warp/public/110/38.html

After this is set up, then you can do the client tunnels.  Here's the article I used to set up mine:
http://www.cisco.com/warp/public/110/pixpixvpn.html

Let me know what you think.

<-=+=->
0
 
LVL 15

Expert Comment

by:Joseph Hornsey
ID: 16957185
Oh, yeah... one more thing.

Regarding not allowing them to access the internet.

That's going to be configured on whichever PIX they're connecting to with their VPN client.  To really help, I think I need more clarification on what you're trying to do there.

If, for example, you want them to access the internet only through your LAN (via the VPN), you can pretty much leave everything alone.
If, however, you want them to access the internet through THEIR network and not the VPN, then you have to configure Split Tunneling.
If, on the other hand, you don't want them to access the internet at all, then you'll have to manage that with your ACL.

Hope that helps.

<-=+=->
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 2000 total points
ID: 16957655
Take a peek into this post;

http://www.experts-exchange.com/Networking/Microsoft_Network/Q_21892134.html

Question 1: Disable internet access when they are connected ( I presume that you mean their local vpn connection).

In this case, remove the split tunneling and then all the connections will go through your VPN sessions; no vpn-group <group> split <acl-name>

Question 2: Connect to A and access B also.

To make a U-turn like this you need to have 7.0 version of the software which I assume you don't have right now. It is not possible, sorry!

Cheers,
Rajesh
0

Featured Post

Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

601 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question