PIX501 VPN Troubles
Posted on 2007-03-19
Hello, I am relatively new to the PIX501. We have established two of these units as routers at different locations and both work fine. We have port forwarding and basic internet access working. I am now trying to setup a VPN between the two. Both have static iP addresses from the ISP.
So far, my only attempts have been to run the wizards in the device manager. First of all I setup the PIX to communicate with the Cisco VPN client. That works fine.
When I go to setup the VPN between two units, I follow the wizard, providing all necessary information. It seems to work properly, but once I complete work on the wizard, two things happen (or do not). First, the VPN light does not turn on. Secondly, I lose access to the internet from all computers inside the PIX. It is not just loss of sites like google.com, but I can also not ping IP addresses directly, so I don't think it has anything to do with DNS. This happens on both PIXs. If I go into the VPN configuration and delete the tunnel policy that was setup, then I regain internet access without any problems.
I am looking for any pointers which may help me better understand what is causing me to lose connection, what I can do to regain it, and eventually any help on establishing the VPN. Note; the only thing I did to regain outside access was to delete the tunnel policy and click Apply. Access rules seem to be setup fine and work without the tunnel policy in place.
Device: Cisco PIX 501 Firewall
Device Manager: Cisco PIX Device Manger 3.0(4)
PIX Version: 6.3(5)
OS: Windows XP
Modem: Westell Wirespeed C90 Series
Thanks for any help