Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco Pix 506 VPN -

Posted on 2012-04-03
5
Medium Priority
?
292 Views
Last Modified: 2014-10-20
Hi there
I currently have a Cisco Pix 506 device which has site-to-site vpns to multiple sites across the world. It also terminates Client vpns to that device. Now, one of the vpn users requires access connecitity to another site through the vpn client and across the site-to-site. The problem is, there is no reverse-path defined on the other site to direct back to the vpn subnet on the local router and there is no way to add one.
Is it possible to NAT a clients vpn address to the local lan ip so when it is sent to the other site it can return.

Any questions please let me know.

Thanks for your time.
0
Comment
Question by:admerritt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 1000 total points
ID: 37805573
Not with a Pix 500 series sorry - you need to be running version 7 - which is ASA only Im afraid sorry :(

Cisco Firewall VPN "Hair Pinning"

Pete
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 1000 total points
ID: 37805783
To clarify:

Q. Which devices support PIX 7.x?

A. PIX 515, PIX 515E, PIX 525, PIX 535 and all of the Cisco ASA 5500 Series Adaptive Security Appliances (ASA 5510, ASA 5520, and ASA 5540) support software version 7.x and later.
The PIX 501, PIX 506E, and PIX 520 Security Appliances are not supported in software version 7.x.


Source: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a00805b87d8.shtml

Though it seems there are 'creative' ways to get to 7.0x : http://www.techexams.net/forums/ccnp-security/16730-cisco-pix-506-a.html
But I don't know if you want to go that far.......

And because it's almost getting end-of-everything: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/ps4336/prod_eol_notice0900aecd80731dfa.html

You might want to consider to get a new(er) one.
0
 
LVL 15

Expert Comment

by:Robert Sutton Jr
ID: 37811855
Agreed. It isn't possible with the device you currently own.
0

Featured Post

Protect Your Retail Business and Reputatio

Wi-Fi access doesn't just impact your business & customer experience, it can also affect your security.  Join us for a webinar on Sept. 28th to learn more about the top threats and trends impacting retail today, and the key solutions to protecting retail networks and reputations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

660 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question