<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Concentrator/multiple PIXes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/concentrator-multiple-pixes/m-p/408954#M529817</link>
    <description>&lt;P&gt;Two networks behind a concentrator, 10.10.10.x and 192.168.96.x. The Pix is on the 192, and a router with NAT disabled (transparent) routes to the 10.10. Multiple PIX 501s are all in the 192.168.97.x to 192.168.125.x range, no overlaps. Traffic comes in to the concentrator, and to the 192 side, but not to the 10 side, and no traffic back out. Pulling our hair out here. Any help appreciated. Configs will follow if you think you have an idea, or experience in this.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:34:37 GMT</pubDate>
    <dc:creator>jreusch</dc:creator>
    <dc:date>2020-02-21T08:34:37Z</dc:date>
    <item>
      <title>Concentrator/multiple PIXes</title>
      <link>https://community.cisco.com/t5/network-security/concentrator-multiple-pixes/m-p/408954#M529817</link>
      <description>&lt;P&gt;Two networks behind a concentrator, 10.10.10.x and 192.168.96.x. The Pix is on the 192, and a router with NAT disabled (transparent) routes to the 10.10. Multiple PIX 501s are all in the 192.168.97.x to 192.168.125.x range, no overlaps. Traffic comes in to the concentrator, and to the 192 side, but not to the 10 side, and no traffic back out. Pulling our hair out here. Any help appreciated. Configs will follow if you think you have an idea, or experience in this.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/concentrator-multiple-pixes/m-p/408954#M529817</guid>
      <dc:creator>jreusch</dc:creator>
      <dc:date>2020-02-21T08:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Concentrator/multiple PIXes</title>
      <link>https://community.cisco.com/t5/network-security/concentrator-multiple-pixes/m-p/408955#M529822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. on the main office pix, verify whether there is a route pointing to the router for net 10.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. on the router, verify whether the default route is set to the pix interface; or routes pointing to the pix for remote nets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. verify the no-nat and crypto acl on concentrator and remote pixes.&lt;/P&gt;&lt;P&gt;e.g. on the remote pix,&lt;/P&gt;&lt;P&gt;access-list no_nat permit ip &lt;REMOTE net=""&gt; &lt;REMOTE net="" mask=""&gt; 192.168.96.0 255.255.255.0&lt;/REMOTE&gt;&lt;/REMOTE&gt;&lt;/P&gt;&lt;P&gt;access-list no_nat permit ip &lt;REMOTE net=""&gt; &lt;REMOTE net="" mask=""&gt; 10.10.10.0 255.255.255.0&lt;/REMOTE&gt;&lt;/REMOTE&gt;&lt;/P&gt;&lt;P&gt;access-list l2lvpn permit ip &lt;REMOTE net=""&gt; &lt;REMOTE net="" mask=""&gt; 192.168.96.0 255.255.255.0&lt;/REMOTE&gt;&lt;/REMOTE&gt;&lt;/P&gt;&lt;P&gt;access-list l2lvpn permit ip &lt;REMOTE net=""&gt; &lt;REMOTE net="" mask=""&gt; 10.10.10.0 255.255.255.0&lt;/REMOTE&gt;&lt;/REMOTE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2005 02:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/concentrator-multiple-pixes/m-p/408955#M529822</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-12-07T02:54:06Z</dc:date>
    </item>
  </channel>
</rss>

