Avatar of sloth10k
sloth10k
 asked on

Routing into a VPN endpoint and back out another firewall

I have a number of remote users VPNing into our internal network through a Cisco PIX endpoint.  Currently, their web traffic is directed through their remote user VPN tunnel to a proxy server.  For example, their browser points to the proxy server, and the proxy communicates out.

I would like to change this configuration so that web traffic goes out another firewall that does not function as a proxy.  This firewall will be used for logging and filtering, so I do not want to use split tunneling to allow remote users to directly access the internet, and I would prefer that web traffic not go right back out the PIX.

I'm running into a routing problem on the PIX.  The PIX's default route is on its outside interface, so that it can communicate with any remote user.  It has static routes defined on its inside interface to access internal network resources, including the proxy server mentioned above.  However, when web traffic (with random IPs) is sent from a remote user down their VPN tunnel, there is no internal route on the PIX directing this traffic to the new firewall.

If I could define a different default gateway for remote user VPN tunnels, that might do the trick.  Forgive me if I'm missing something obvious...
Network ArchitectureNetworking Hardware-Other

Avatar of undefined
Last Comment
asavener

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
asavener

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck