<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN clients being able to access already setup tunnels in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253277#M1060212</link>
    <description>&lt;P&gt;Hi everybody, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a central site with one 506E Pix and 5 remote sites connected using 501E Pix (IpSec Tunnels). Now I have to permit VPN clients to connect to the central site (no problem for this) but also they have to be able to access the remote sites, at least one of them. &lt;/P&gt;&lt;P&gt;For what I know, this can't be done using a 506E Pix but my question is... If got a 515E Pix with three interfaces could this be solved? &lt;/P&gt;&lt;P&gt;I would appreciate you answered me or suggested any other solution for the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all in advanced! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:13:52 GMT</pubDate>
    <dc:creator>pression2</dc:creator>
    <dc:date>2020-02-21T07:13:52Z</dc:date>
    <item>
      <title>VPN clients being able to access already setup tunnels</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253277#M1060212</link>
      <description>&lt;P&gt;Hi everybody, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a central site with one 506E Pix and 5 remote sites connected using 501E Pix (IpSec Tunnels). Now I have to permit VPN clients to connect to the central site (no problem for this) but also they have to be able to access the remote sites, at least one of them. &lt;/P&gt;&lt;P&gt;For what I know, this can't be done using a 506E Pix but my question is... If got a 515E Pix with three interfaces could this be solved? &lt;/P&gt;&lt;P&gt;I would appreciate you answered me or suggested any other solution for the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all in advanced! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253277#M1060212</guid>
      <dc:creator>pression2</dc:creator>
      <dc:date>2020-02-21T07:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients being able to access already setup tunnels</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253278#M1060213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about creating another connection entry on your VPN client and configuring the 506 for accepting client connections. All that the remote user has to do is to choose the appropriate connection entry and connect using it. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2004 15:02:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253278#M1060213</guid>
      <dc:creator>drolemc</dc:creator>
      <dc:date>2004-02-12T15:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients being able to access already setup tunnels</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253279#M1060214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 506E on central site is already configured to accept vpn connections. &lt;/P&gt;&lt;P&gt;The problem is that it connects on the outside interface of the Pix and therefore it cannot use the already setup tunnels used by the remote sites. &lt;/P&gt;&lt;P&gt;If you meant setting up several client connecting, each one of them pointing to the remote sites PIX's, the answer is Yes I can do that, but I want to make it simple for the user so he can establish a vpn client connection and have access to the entire network (or at least to one remote site).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2004 15:32:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253279#M1060214</guid>
      <dc:creator>pression2</dc:creator>
      <dc:date>2004-02-12T15:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients being able to access already setup tunnels</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253280#M1060215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont think it is possible with any kind of PIX. Simply cause PIX cant route traffic coming from one interface and route it back to same interface. which means traffic coming from one VPN tunnel cant go out to another tunnel. You can use a Router making it a hub and rest being spoke. With router you will be able to acheive what you are trying to do. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Mar 2004 19:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253280#M1060215</guid>
      <dc:creator>shabib.syed</dc:creator>
      <dc:date>2004-03-03T19:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients being able to access already setup tunnels</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253281#M1060217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/tech/tk583/tk372/technologies_configuration_example09186a0080103ed0.shtml" target="_blank"&gt;http://www.cisco.com/en/US/customer/tech/tk583/tk372/technologies_configuration_example09186a0080103ed0.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gives an explaination on how to hack together this solution&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Mar 2004 16:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253281#M1060217</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2004-03-05T16:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients being able to access already setup tunnels</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253282#M1060221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm agreeing with proposed solution. Good news also that PIX firmware 6.3 support VLANs. So you do not need separate physical interfaces. Possible next releases solve problems with VPN tunnel routing. Most firewall vendors made this decision - allow VPN routing through the HUB.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2004 19:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-being-able-to-access-already-setup-tunnels/m-p/253282#M1060221</guid>
      <dc:creator>sergej.gurenko</dc:creator>
      <dc:date>2004-03-11T19:47:45Z</dc:date>
    </item>
  </channel>
</rss>

