cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
287
Views
0
Helpful
1
Replies

Allow HOME USERS ACCESS PIX 515

admin_2
Level 3
Level 3

Can someone share with me the command or configuration I need to allow home users access over the PIX without going through our proxy.

First of all everything is working fine even home users can access our network and internet from their home by dialing up to Cisco Secure ACS and then going on to our ISA server. Now in the office I have configured my PC with static IP that allows me to access the Internet directly without going through our proxy server. I need this same type of access from the home also.

Any suggestions?

1 Reply 1

ehirsel
Level 6
Level 6

Will the home users still dial-in to a NAS? If not, and the home users and the internet connection will be using the same pix interface then I do not believe that it could work, due to the pix not being able to do the routing back thru the same interface.

If the users will still dial-in, then yes, you can do that. Assuming that the NAS sits on a perimiter inteface off of the pix, you could use a nat (dmz) ii diall-in-user-ip dial-subnet and a global (outside) ii x.x.x.x command to do nat/pat for the dial-up users. This eliminates the proxy connection.

Review Cisco Networking for a $25 gift card