07-12-2005 04:26 AM - edited 02-21-2020 12:15 AM
Hi,
I'm trying to do a site - site pix 501 vpn connection.
One of the VPN's sits behind a cisco adsl 837 router and I'm struggling to get the site-site vpn running.
How should I set it up, any ideas as the adsl router uses nat and then the pix does too.
cheers
Rob
07-12-2005 06:20 AM
Hi Rob,
How's things?
Have you got NAT traversal configured on the PIX which wraps the IPSEC packets in a UDP header (4500) thus allowing the encrypted packets to be NATed.
NAT-T is negotiated during Phase1 (isakmp)
On the PIX it will be:
isakmp nat-traversal
HTH
PJD
07-12-2005 07:04 AM
Hi Paddy, thanks for that!
How would I have the 837 set up to accommodate this?
I have 5 global IP addresses form the dsl ISP and would like to VPN one of them onto a 172.18.124.0/24 ip range.
Don't suppose you've got a sample config for the pix 501 and the 837 knocking around have ya as am pulling me hair out over here?
cheers matey!!!
07-12-2005 08:09 AM
Hi Paddy,
Are you available for tech support on cisco kit, particularly pix's and vpn's?
My email address is rob@webstyleinternet.com.
07-12-2005 08:14 AM
Have a look at the following link:
HTH
Paddy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide