Solved

Cisco Pix to Pix VPN with 4.x VPN Client

Posted on 2006-06-21
3
327 Views
Last Modified: 2010-03-19
I have two offices, A & B that are connected through a Pix-to-Pix VPN.  All traffic runs great through this.  I have VPN client access at each of these Pixes as well, can connect to either A or B and see the local network.  I need to provide access for users to connect with a client VPN to office A and be able to access resources in office B.  When a user is connected the the VPN, they must not have access to the Internet.  Any insight on this would be great.

Thanks


VPN CLIENT ------ Office A ---------- Office B --------- VPN CLIENT
0
Comment
Question by:netspheretech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 14

Expert Comment

by:Joseph Hornsey
ID: 16957166
I had to set this up recently.

Here's basically what you do.

First, set up your PIX-to-PIX VPN tunnel (if it isn't already set up - sounds like it is).  If it isn't, then a great doc is here:
http://www.cisco.com/warp/public/110/38.html

After this is set up, then you can do the client tunnels.  Here's the article I used to set up mine:
http://www.cisco.com/warp/public/110/pixpixvpn.html

Let me know what you think.

<-=+=->
0
 
LVL 14

Expert Comment

by:Joseph Hornsey
ID: 16957185
Oh, yeah... one more thing.

Regarding not allowing them to access the internet.

That's going to be configured on whichever PIX they're connecting to with their VPN client.  To really help, I think I need more clarification on what you're trying to do there.

If, for example, you want them to access the internet only through your LAN (via the VPN), you can pretty much leave everything alone.
If, however, you want them to access the internet through THEIR network and not the VPN, then you have to configure Split Tunneling.
If, on the other hand, you don't want them to access the internet at all, then you'll have to manage that with your ACL.

Hope that helps.

<-=+=->
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 16957655
Take a peek into this post;

http://www.experts-exchange.com/Networking/Microsoft_Network/Q_21892134.html

Question 1: Disable internet access when they are connected ( I presume that you mean their local vpn connection).

In this case, remove the split tunneling and then all the connections will go through your VPN sessions; no vpn-group <group> split <acl-name>

Question 2: Connect to A and access B also.

To make a U-turn like this you need to have 7.0 version of the software which I assume you don't have right now. It is not possible, sorry!

Cheers,
Rajesh
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
This program is used to assist in finding and resolving common problems with wireless connections.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question