Solved

Cisco Pix 506 VPN -

Posted on 2012-04-03
5
281 Views
Last Modified: 2014-10-20
Hi there
I currently have a Cisco Pix 506 device which has site-to-site vpns to multiple sites across the world. It also terminates Client vpns to that device. Now, one of the vpn users requires access connecitity to another site through the vpn client and across the site-to-site. The problem is, there is no reverse-path defined on the other site to direct back to the vpn subnet on the local router and there is no way to add one.
Is it possible to NAT a clients vpn address to the local lan ip so when it is sent to the other site it can return.

Any questions please let me know.

Thanks for your time.
0
Comment
Question by:admerritt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 250 total points
ID: 37805573
Not with a Pix 500 series sorry - you need to be running version 7 - which is ASA only Im afraid sorry :(

Cisco Firewall VPN "Hair Pinning"

Pete
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 250 total points
ID: 37805783
To clarify:

Q. Which devices support PIX 7.x?

A. PIX 515, PIX 515E, PIX 525, PIX 535 and all of the Cisco ASA 5500 Series Adaptive Security Appliances (ASA 5510, ASA 5520, and ASA 5540) support software version 7.x and later.
The PIX 501, PIX 506E, and PIX 520 Security Appliances are not supported in software version 7.x.


Source: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a00805b87d8.shtml

Though it seems there are 'creative' ways to get to 7.0x : http://www.techexams.net/forums/ccnp-security/16730-cisco-pix-506-a.html
But I don't know if you want to go that far.......

And because it's almost getting end-of-everything: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/ps4336/prod_eol_notice0900aecd80731dfa.html

You might want to consider to get a new(er) one.
0
 
LVL 15

Expert Comment

by:Robert Sutton Jr
ID: 37811855
Agreed. It isn't possible with the device you currently own.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
2-Factor authentication VPN for staff and suppliers 6 89
site - site VPN 3 77
VPN Server Configuration in windows 7 7 71
HP 2530 switch and routing 4 95
If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question