Can I establish VPN tunnels through both the inside and outside interfaces on a Cisco Pix firewall?

Posted on 2010-08-15
Last Modified: 2012-05-10
I currently operate an Internet based WAN with fixed Pix to Pix VPN connections between sites. I am migrating to an MPLS based WAN. While some sites will ditch the firewall and replace it with the MPLS router, others will move the outside interface of their firewall from the Internet router to the MPLS router. During the migration, my location will maintain a direct connection to the MPLS and a firewalled connection to the local Internet service.

My question is: When a remote firewall is moved from Internet to MPLS, can I establish a new tunnel via the inside interface of my Pix, while still maintaining other external VPN tunnels. This would mean, at my end, both encrypted and unencrypted traffic would use the same interface.
Question by:andy_belton
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 20

Expert Comment

ID: 33443250
You are using a VPN tunnel through the mpls?  Why?  Mpls is private.  You don't need a virtual private network (VPN) on a private network.

Anyway, migrating means that hq should be a bridge between mpls and IPSec networks.  Just remove from pix and route as a normal route.

Author Comment

ID: 33443804
I have 2 zones within the MPLS, "private" and "Very private". I am in "Private" but I need to be able to provide admin and support to servers and wkstns in "Very private". Untill all sites are on MPLS, the quickest solution would be to switch VPN tunnel from outside to inside interface when a "Very private" site joins the MPLS. I don't need to know how to do it, just if it is possible. I don't want to spend time reconfiguring the firewall if it turns out that such a configuration will not be permitted by ther Pix.
LVL 20

Expert Comment

ID: 33444628
I'm not sure I get what you mean.

I would recommend enabling IPSec on the very private workstations & server and leave the pix out of it.
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.


Author Comment

ID: 33445762
See attached diagram.

The top scenario shows what it is like now. the Private WAN has been created but all remote sites are suopported using VPNs.

The lower scenario shows How I would like it to be after some sites have been transferred to the WAN. IT Support can access Private LAN A directly without any VPN. Very Private LAN B still has its own firewall in place but the outside of it is connected to the WAN. Is it possible for IT support to access Very Private LAN B by VPN from their local firewall, when the VPN is routed back through the same interface (Inside).

LVL 20

Accepted Solution

RPPreacher earned 500 total points
ID: 33445969
Won't work.

Author Closing Comment

ID: 33446079
It wasn't what I wanted to hear, but it will save me the futile exercise of trying to configure it that way.

Thank you very much fior the advice.

Featured Post

Supports up to 4K resolution!

The VS192 2-Port 4K DisplayPort Splitter is perfect for anyone who needs to send one source of DisplayPort high definition video to two or four DisplayPort displays. The VS192 can split and also expand DisplayPort audio/video signal on two or four DisplayPort monitors.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month5 days, 19 hours left to enroll

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question