Solved

Can I establish VPN tunnels through both the inside and outside interfaces on a Cisco Pix firewall?

Posted on 2010-08-15
6
416 Views
Last Modified: 2012-05-10
I currently operate an Internet based WAN with fixed Pix to Pix VPN connections between sites. I am migrating to an MPLS based WAN. While some sites will ditch the firewall and replace it with the MPLS router, others will move the outside interface of their firewall from the Internet router to the MPLS router. During the migration, my location will maintain a direct connection to the MPLS and a firewalled connection to the local Internet service.

My question is: When a remote firewall is moved from Internet to MPLS, can I establish a new tunnel via the inside interface of my Pix, while still maintaining other external VPN tunnels. This would mean, at my end, both encrypted and unencrypted traffic would use the same interface.
0
Comment
Question by:andy_belton
  • 3
  • 3
6 Comments
 
LVL 20

Expert Comment

by:RPPreacher
ID: 33443250
You are using a VPN tunnel through the mpls?  Why?  Mpls is private.  You don't need a virtual private network (VPN) on a private network.

Anyway, migrating means that hq should be a bridge between mpls and IPSec networks.  Just remove from pix and route as a normal route.
0
 

Author Comment

by:andy_belton
ID: 33443804
I have 2 zones within the MPLS, "private" and "Very private". I am in "Private" but I need to be able to provide admin and support to servers and wkstns in "Very private". Untill all sites are on MPLS, the quickest solution would be to switch VPN tunnel from outside to inside interface when a "Very private" site joins the MPLS. I don't need to know how to do it, just if it is possible. I don't want to spend time reconfiguring the firewall if it turns out that such a configuration will not be permitted by ther Pix.
0
 
LVL 20

Expert Comment

by:RPPreacher
ID: 33444628
I'm not sure I get what you mean.

I would recommend enabling IPSec on the very private workstations & server and leave the pix out of it.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:andy_belton
ID: 33445762
See attached diagram.

The top scenario shows what it is like now. the Private WAN has been created but all remote sites are suopported using VPNs.

The lower scenario shows How I would like it to be after some sites have been transferred to the WAN. IT Support can access Private LAN A directly without any VPN. Very Private LAN B still has its own firewall in place but the outside of it is connected to the WAN. Is it possible for IT support to access Very Private LAN B by VPN from their local firewall, when the VPN is routed back through the same interface (Inside).

Network-Now-and-during-transitio.jpg
0
 
LVL 20

Accepted Solution

by:
RPPreacher earned 500 total points
ID: 33445969
Won't work.
0
 

Author Closing Comment

by:andy_belton
ID: 33446079
It wasn't what I wanted to hear, but it will save me the futile exercise of trying to configure it that way.

Thank you very much fior the advice.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now