Solved

Cisco Pix to Pix VPN with 4.x VPN Client

Posted on 2006-06-21
3
322 Views
Last Modified: 2010-03-19
I have two offices, A & B that are connected through a Pix-to-Pix VPN.  All traffic runs great through this.  I have VPN client access at each of these Pixes as well, can connect to either A or B and see the local network.  I need to provide access for users to connect with a client VPN to office A and be able to access resources in office B.  When a user is connected the the VPN, they must not have access to the Internet.  Any insight on this would be great.

Thanks


VPN CLIENT ------ Office A ---------- Office B --------- VPN CLIENT
0
Comment
Question by:netspheretech
  • 2
3 Comments
 
LVL 13

Expert Comment

by:Joseph Hornsey
ID: 16957166
I had to set this up recently.

Here's basically what you do.

First, set up your PIX-to-PIX VPN tunnel (if it isn't already set up - sounds like it is).  If it isn't, then a great doc is here:
http://www.cisco.com/warp/public/110/38.html

After this is set up, then you can do the client tunnels.  Here's the article I used to set up mine:
http://www.cisco.com/warp/public/110/pixpixvpn.html

Let me know what you think.

<-=+=->
0
 
LVL 13

Expert Comment

by:Joseph Hornsey
ID: 16957185
Oh, yeah... one more thing.

Regarding not allowing them to access the internet.

That's going to be configured on whichever PIX they're connecting to with their VPN client.  To really help, I think I need more clarification on what you're trying to do there.

If, for example, you want them to access the internet only through your LAN (via the VPN), you can pretty much leave everything alone.
If, however, you want them to access the internet through THEIR network and not the VPN, then you have to configure Split Tunneling.
If, on the other hand, you don't want them to access the internet at all, then you'll have to manage that with your ACL.

Hope that helps.

<-=+=->
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 16957655
Take a peek into this post;

http://www.experts-exchange.com/Networking/Microsoft_Network/Q_21892134.html

Question 1: Disable internet access when they are connected ( I presume that you mean their local vpn connection).

In this case, remove the split tunneling and then all the connections will go through your VPN sessions; no vpn-group <group> split <acl-name>

Question 2: Connect to A and access B also.

To make a U-turn like this you need to have 7.0 version of the software which I assume you don't have right now. It is not possible, sorry!

Cheers,
Rajesh
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
policy routing to fw2 18 52
Configuring routing and ACL for Cisco 891 router 15 47
Cisco ASA 5505 Login issues 2 25
EIGRP STUB 19 42
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now