<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX Case outside inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-case-outside-inside/m-p/855739#M494925</link>
    <description>&lt;P&gt;Hi there, attached is what i want to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to:&lt;/P&gt;&lt;P&gt;1.start a vpn site to site with the pix firewall A and the Checkpoint VPN.&lt;/P&gt;&lt;P&gt;2.pc has to connect to PC 3(via the VPN)and also to PC1 on the Lan ext.&lt;/P&gt;&lt;P&gt;3. For testing i want pc1 and pc3 to be able to ping PC2 and vice versa, pc2 to ping pc3 and pc1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can this be established? how can i do this. can some one point me in the right direction? Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:45:51 GMT</pubDate>
    <dc:creator>greg-bnets</dc:creator>
    <dc:date>2020-02-21T09:45:51Z</dc:date>
    <item>
      <title>PIX Case outside inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-case-outside-inside/m-p/855739#M494925</link>
      <description>&lt;P&gt;Hi there, attached is what i want to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to:&lt;/P&gt;&lt;P&gt;1.start a vpn site to site with the pix firewall A and the Checkpoint VPN.&lt;/P&gt;&lt;P&gt;2.pc has to connect to PC 3(via the VPN)and also to PC1 on the Lan ext.&lt;/P&gt;&lt;P&gt;3. For testing i want pc1 and pc3 to be able to ping PC2 and vice versa, pc2 to ping pc3 and pc1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can this be established? how can i do this. can some one point me in the right direction? Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:45:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-case-outside-inside/m-p/855739#M494925</guid>
      <dc:creator>greg-bnets</dc:creator>
      <dc:date>2020-02-21T09:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Case outside inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-case-outside-inside/m-p/855740#M494926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi  ..  OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's divide this in two tasks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.-  Communication between PC1 and PC2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* on the PIX You need a static NAT entry for PC2 as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside1) PC2-Real-IP-Address PC2-Real-IP-Address netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* allow access from PC1 to PC2&lt;/P&gt;&lt;P&gt;access-list outside1_inside permit icmp host PC1 host PC2-Real-IP-Address&lt;/P&gt;&lt;P&gt;access-group outside1_inside in interface outside1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* If you have an access list applied to the inside interface then you need &lt;/P&gt;&lt;P&gt;to add an entry that allows icmp access from PC2 to PC1  i.e&lt;/P&gt;&lt;P&gt;access-list inside-out permit icmp host PC2-Real-IP-Address host PC1&lt;/P&gt;&lt;P&gt;access-group inside-out in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* You might need to add a static route on the firewall for 192.168.3.0/24&lt;/P&gt;&lt;P&gt;route outside1 192.168.3.0 255.255.255.0 10.10.40.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* Make sure any other devices between those segments know how to get to each other&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.-  Communication between PC2 and PC3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you clarify ..  is the VPN between routerA and Checkpoint already UP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if it is then we would need to have a look at the config of routerA before sugggesting &lt;/P&gt;&lt;P&gt;next steps to follow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps   ..  please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2007 22:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-case-outside-inside/m-p/855740#M494926</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2007-11-07T22:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Case outside inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-case-outside-inside/m-p/855741#M494927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ferando.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did some home work and resolved the issue. But thanks for the help anyway. i will still rate for you. What i still have is that with the VPN my site can only initiate the tunnel to be up. Lets only if i start pinging the other side, they can ping me back. How can i keep the tunnel up 24/7?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2007 19:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-case-outside-inside/m-p/855741#M494927</guid>
      <dc:creator>greg-bnets</dc:creator>
      <dc:date>2007-11-09T19:15:40Z</dc:date>
    </item>
  </channel>
</rss>

