General questions about PIX 501 to PIX 50 VPN?

Posted on 2007-07-23
Last Modified: 2012-05-05
I am in the process of setting up an IPSec VPN between two PIX 501s.  In the lab I have made the VPN work.

I have several questions which I need answers to.  I do not need to know specifics at this time, just generalities with supporting links would be helpful. (50 points per question)

Question 1:
Can the remote site which is using dynamic DSL be configured to connect to the home site which is using static IP?  I know it can be done if the home site is a Cisco concentrator, but will it work if the home site is a Cisco PIX 501?

Question 2:
Can the vpn tunnel be made to activate automatically without the requirement for interesting traffic to be sent?

Question 3:
If question 2 is true can the tunnel be made to never time out?

Question 4:
Once the tunnel is up, is the dhcprelay command required for the user pc at the remote site to request an IP address from a dhcp server at the home site?

Question 5:
As a general rule does an IPSec vpn allow ALL traffic to pass through in both directions as long as an ACL allows it?
Question by:dalva
    LVL 57

    Assisted Solution

    by:Pete Long
    LVL 57

    Assisted Solution

    by:Pete Long
    2 Yes but you would need to add an isakmp keepalive to the Tunnel to do this (it keeps the tunnel up)


     isakmp keepalive 10

    LVL 57

    Accepted Solution

    3. Yes see above

    4. No see number 1 :)

    5. NO! but once you have the following command it does

    sysopt connection permit-ipsec

    LVL 57

    Expert Comment

    by:Pete Long

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
    Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now