I am attmepting to setup a second site to site VPN tunnel on a Cisco Pix 501. I am having trouble with it. This is first time where the destination fiewall (cisco ASA) subnet is not a private subnet and I believe this is throwing me off.
The ASA's firewall IP is 204.xxx.xx8.249, whereas its subnet that I need to communicate with is 204.xxx.xx9.0. The local subnet on the Pix is 192.168.73.x.
I turned on the logging and this is the only thing I am seeing.
The Pix is running 6.3.5.
If you mean IKE peers, that is showing we are licensed for 10.
The ASA on the other side is using something like this, but I dont know how to implement this on the Pix since I am going to have multiple tunnels.
nat (inside) 0 access-list 101
Can this command be entered multiple times for different access lists?
When I use a nat 0 for multiple tunnels, I've always just added the source and dest to the same nat0 acl. I don't think you can have multiple Nat 0 on the same interface since it would probably mess with how the ACLs are processed, which ACL would be applied 1st, etc...
BTW, having a non-private range as the destination of a VPN tunnel makes no difference. Your firewall doesn't care, it will match the destination to the ACL and nonat it, or catch it in the crypto match....
Everything looks ok to me. Any chance we can see the code or some logs on the far end of this tunnel
We were able to get this working. I had the config on the ASA rebuilt and the tunnel then came up. Thanks for the help!
0
Featured Post
WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network. Check out this quarters report on the threats that shook the industry in Q4 2017.
WARNING:
If you follow the instructions here, you will wipe out your VTP and VLAN configurations. Make sure you have backed up your switch!!!
I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal.
As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …