2 Cisco PIX connected to same ISP connection

Posted on 2012-09-21
Last Modified: 2012-10-02

I'm trying to create a VPN tunnel to my other site. The PIX 515E Firewall  currently in use has a restricted license, so I cannot add another interface to it. I also have VPN client users that connect through this FW. When I had the site-to-site working before, the VPN users were not able to connect since the other tunnel was active.

I purchased another 515E FW, assuming I could bind another ISP address to 1 interface and be on my way. This plan was also assuming I could split the ISP connection with a basic switch and have both firewalls connected at the same time. Of course, it didn't work out this way. When I have both FWs connected at the same time, both external interfaces go up and down every couple seconds.

Is there something I am missing here or is this just not possible? I added a basic diagram so you could see what I am trying to accomplish here.


             |-----Switch----ISP Cisco 1841 Router
Question by:Matt Russell

    Author Comment

    by:Matt Russell
    As I thought more about this, a better question would be if my main PIX can do handle both VPN types terminating at the same interface without killing the other?
    LVL 36

    Assisted Solution

    you can have site to site and remote access VPN connections on the same pix at the same time

    you can have two pix connected to the same ISP at the same time, but unless they are configured as a failover cluster, they each need their own external and internal IP addresses

    a suitably sanitized copy of the config would be useful

    Author Comment

    by:Matt Russell
    I can get copies of the main PIX config since if I could keep using one with it handling both site-to-site and remote access VPNs, that woud be great.

    Each unit has its own adress, externally and internally. When I connect the 2 PIXs to the same switch, the external interfaces on both start going up and down, killing the internet connection.

    Let me get the config and we can go from there.

    Author Comment

    by:Matt Russell
    Here is a cleaned copy of the config. I re-added the crypto map portions since I had to remove them previously while troubleshooting this issue.

    Thanks for anything you can tell me!

    Accepted Solution

    After doing more research, I figured it out. I had to use the same crypto map for both VPN types. Thanks for trying at least.

    Author Closing Comment

    by:Matt Russell
    My own research independent of this lead to me figuring out the correct solution.

    Featured Post

    Find Ransomware Secrets With All-Source Analysis

    Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

    Join & Write a Comment

    This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
    If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now