Solved

Multiple VPN access using Cisco Pix

Posted on 2006-07-10
2
375 Views
Last Modified: 2013-11-16
Hi
We have a office in US and one in India. We have a IPsec site to site vpn configured and individual Dial UP VPN's for India and US. The problem arises when we dial in to the indian PIX and try to access the us network or vice versa.
I googled and found out that PIX does not route traffic back from the same interface it comes into the network or something like this.
Can somone throw more light on this and also suggest possible solutions.
I understand that one way of doing it is by using VPN concentrator.
Will a version upgrade help? We are presently using Cisco PIX Firewall Version 6.3(1).
Thanks
0
Comment
Question by:siddharthaparti
2 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 250 total points
ID: 17072212
Yes that is true; You can't connect to one pix and make a U-turn through the same interface to get to US network. It is not supported. However, from 7.x version of Pix OS, it is supported. What kind of PIX are we talking about here?

Because 501, 506 stuff don't work on 7.x, so it has to be higher.

Cheers,
Rajesh
0
 
LVL 1

Assisted Solution

by:JEEGO
JEEGO earned 250 total points
ID: 17077394
If you are using a PIX 515 or greater with version 7.x or greater OS, then you should be able to achieve this.
Cisco refer to this as 'hairpinning', and it can be accomplished by adding a couple of ACL lines as well as using the  'intra interface' command
This is very well documented in a CISCO document you can find by copying the link below into you browser address bar

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805734ae.shtml

Hope it helps you out.

JEEGO
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
CISCO refresh sheets 2 35
Routing VLANs 5 47
Site-to-Site VPN Cisco ASA 5505 to Cisco RV320 4 36
Access List 4 14
When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now