PIX 501 Remote VPN setup

osxla
osxla used Ask the Experts™
on
I just setup a remote access VPN in my PIX 501. I attached the config and it seems to be working (can connect to shares, RDP) but I did unchecked the box in the VPN wizard regarding AAA and local database. Is not doing this going to affect anything? Also if you can look at the IP in DHCP pool. Is this correct. The other issue is I dont have internet connection when connected to the VPN. Is this because there is not DNS address in VPN?

Thanks
PIX501-After-VPN-Remote.txt
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Istvan KalmarHead of IT Security Division
Top Expert 2010

Commented:
Hi,
If you use split tunnel you able to reach the internet:

access-list SPLIT_Tunnel standard permit ip 192.168.2.1 255.255.255.0

vpngroup vpnremote address-pool vpnpool
vpngroup vpnremote idle-time 1800
vpngroup vpnremote dns-server x.x.x.x
vpngroup vpnremote wins-server x.x.x.x
vpngroup vpnremote default-domain xxxx.com
vpngroup vpnremote split-tunnel SPLIT_Tunnel
vpngroup vpnremote password ********

Istvan KalmarHead of IT Security Division
Top Expert 2010

Commented:
access-list SPLIT_Tunnel standard permit ip 192.168.2.0 255.255.255.0
Sr. Systems Engineer
Top Expert 2008
Commented:
PIX 501 does not understand "standard" acls, so it has to be modified slightly
try this:
access-list SPLIT_TUNNEL permit ip 192.168.2.0 255.255.255.0 192.168.150.0 255.255.255.252
vpngroup vpnremote split-tunnel SPLIT_TUNNEL
Success in ‘20 With a Profitable Pricing Strategy

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
lrmoore

After adding your statement do I need to add a DNS server that ikalmar recommended or will adding this get it online while connected?

 Also was that set about the local database not important?
Istvan KalmarHead of IT Security Division
Top Expert 2010

Commented:
Hi,
The local database is not ijmportant, if you want to go the internet!

Author

Commented:
What is it used for?

Author

Commented:
adding this worked.
access-list SPLIT_TUNNEL permit ip 192.168.2.0 255.255.255.0 192.168.150.0 255.255.255.252
vpngroup vpnremote split-tunnel SPLIT_TUNNEL

Just wondering what the local database option was used for in vpn setup wizard?
Istvan KalmarHead of IT Security Division
Top Expert 2010
Commented:
The dns use for local dns for your inside network!
Istvan KalmarHead of IT Security Division
Top Expert 2010

Commented:
users authenticate from local database

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial