Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Cisco Pix to Pix VPN with 4.x VPN Client

Posted on 2006-06-21
3
Medium Priority
?
330 Views
Last Modified: 2010-03-19
I have two offices, A & B that are connected through a Pix-to-Pix VPN.  All traffic runs great through this.  I have VPN client access at each of these Pixes as well, can connect to either A or B and see the local network.  I need to provide access for users to connect with a client VPN to office A and be able to access resources in office B.  When a user is connected the the VPN, they must not have access to the Internet.  Any insight on this would be great.

Thanks


VPN CLIENT ------ Office A ---------- Office B --------- VPN CLIENT
0
Comment
Question by:netspheretech
  • 2
3 Comments
 
LVL 14

Expert Comment

by:Joseph Hornsey
ID: 16957166
I had to set this up recently.

Here's basically what you do.

First, set up your PIX-to-PIX VPN tunnel (if it isn't already set up - sounds like it is).  If it isn't, then a great doc is here:
http://www.cisco.com/warp/public/110/38.html

After this is set up, then you can do the client tunnels.  Here's the article I used to set up mine:
http://www.cisco.com/warp/public/110/pixpixvpn.html

Let me know what you think.

<-=+=->
0
 
LVL 14

Expert Comment

by:Joseph Hornsey
ID: 16957185
Oh, yeah... one more thing.

Regarding not allowing them to access the internet.

That's going to be configured on whichever PIX they're connecting to with their VPN client.  To really help, I think I need more clarification on what you're trying to do there.

If, for example, you want them to access the internet only through your LAN (via the VPN), you can pretty much leave everything alone.
If, however, you want them to access the internet through THEIR network and not the VPN, then you have to configure Split Tunneling.
If, on the other hand, you don't want them to access the internet at all, then you'll have to manage that with your ACL.

Hope that helps.

<-=+=->
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 2000 total points
ID: 16957655
Take a peek into this post;

http://www.experts-exchange.com/Networking/Microsoft_Network/Q_21892134.html

Question 1: Disable internet access when they are connected ( I presume that you mean their local vpn connection).

In this case, remove the split tunneling and then all the connections will go through your VPN sessions; no vpn-group <group> split <acl-name>

Question 2: Connect to A and access B also.

To make a U-turn like this you need to have 7.0 version of the software which I assume you don't have right now. It is not possible, sorry!

Cheers,
Rajesh
0

Featured Post

Identify and Prevent Potential Cyber-threats

Become the white hat who helps safeguard our interconnected world. Transform your career future by earning your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…

783 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question