?
Solved

PIX 506e Allow VPN traffic for Vender

Posted on 2007-08-03
2
Medium Priority
?
299 Views
Last Modified: 2010-04-09
I have a vender that needs to set up a VPN that will pass through my pix 506e firewall the vender requested the following:

Outbound from router 10.1.1.0
Udp 4500 to 192.168.1.1
GRE to 192.168.1.1
Udp 500 to 192.168.1.1
And esp to 192.168.1.1

Inbound from 192.168.1.1
Udp 4500 to 10.1.1.0
GRE to 10.1.1.0
Udp 500 to 10.1.1.0
And esp to 10.1.1.0

They vender also requests that I give them one to one address translation and not pat.

Can anyone provide the commands I need to run on the firewall?

Thanks
0
Comment
Question by:dupont2406
2 Comments
 
LVL 32

Expert Comment

by:rsivanandan
ID: 19629917
First, do you have a free public ip that is not used ?

Second, can you draw an ascii diagram here ?

Third, both are private ip addresses so, what will be vendor side public ip ?

Cheers,
Rajesh
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 2000 total points
ID: 19630861
Basic concept here:

all outbound is already allowed, no acls required.
where "outside_in" is your existing acl if you have one
where 12.34.56.7 is a spare public IP address
where 10.1.1.100 is the private ip address of the host inside the network

access-list outside_in permit udp host 192.168.1.1 eq 4500 host 12.34.56.7 eq 4500
access-list outside_in permit udp host 192.168.1.1 eq 500 host 12.34.56.7 eq 500
access-list outside_in permit gre host 192.168.1.1  host 12.34.56.7
access-list outside_in permit esp host 192.168.1.1  host 12.34.56.7
access-group outside_in in interface outside
static (inside,outside) 12.34.56.7 10.1.1.100 netmask 255.255.255.255

0

Featured Post

Receive 1:1 tech help

Solve your biggest tech problems alongside global tech experts with 1:1 help.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month5 days, 20 hours left to enroll

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question