How to renumber PIX 501 inside IP address with VPN tunnel active?

Posted on 2007-10-14
Last Modified: 2010-04-09
We have several offices using PIX 501s with site-to-site VPN going to a PIX 515.  I need to renumber the inside IP addresses while the VPN tunnels are active but when I attempt that, I lose access to the PIX.  Also since the PIX is serving DHCP at its location I have to disable DHCP first.  I tried opening Telnet to an outside IP address and configuring "Management-Access Outside" but that doesn't seem to work either.  Could someone help point me in the right direction?  Your help will be greatly appreciated!

Question by:WTFDon
    LVL 79

    Expert Comment

    You should be able to access the PIX through the PDM on the public IP address, not through the VPN tunnel.
    You can SSH to the outside IP address if you want the command line.

    Author Comment

    Thanks for the quick response, Irmoore!  I tried SSH to the public IP on the PIX but wasn't able to establish a session.  I'm certain I can reconfigure the PIX if I can access it from outside but I didn't pursue this avenue because I was told by a colleague that you couldn't access the PIX 501 outside interface when a vpn tunnel was active.  Was that incorrect?  If so, could you tell me the correct statements to add to the config enabling SSH to be sure I've got them right?  Thanks for your help!
    LVL 79

    Accepted Solution

    to enable ssh:

    aaa authentication ssh console LOCAL
    username yourusername password yourpassword
    ssh outside  <== your IP Address
    ssh timeout 5
    ca generate rsa key 1024


    Author Comment

    That is EXACTLY the answer.  There are just a couple more things though:  You have to be sure to save the rsa key with "ca save all" and disconnect the vpn tunnel at the remote PIX by issuing "no vpnclient enable", access with SSH to make changes and then bring the tunnel back up with "vpnclient enable".  Thanks a mega for your help!

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    Join & Write a Comment

    From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
    Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    755 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now