11-13-2002 07:02 AM - edited 02-20-2020 10:22 PM
We have a Pix 515. We want ot VPN into other customers with the 3.62 client. The IPSec connection completes but we cannot ping or access any hosts on the remote network. Is there anything that needs to be done on the pix to allow this? I am using NAT for the hosts that need to do this so I have a static mapping between a priv and pub address.
11-15-2002 05:41 PM
Are you getting encrypts on your client? Do you know if your getting decrypts/and or encrypts on the remote pix? Finding this out will help figure out which side the problem is on. You will need an access-list on your pix permiting esp from the remote network to your static public ip address.
Kurtis Durrett
11-15-2002 07:18 PM
Kurtis,
Interesting. I will have to check this out on Monday. I'll let you know. Thanks!
11-18-2002 01:47 PM
What did you find out?
11-27-2002 12:50 PM
Kurtis,
The ESP did it! Thank you very much!!! I did a access-list out permit esp any any.
I really appreciate it!
Sincerely,
Alex
11-15-2002 11:04 PM
If your PATing it will not work. You must have a one to one nated address in order to be able to vpn from the inside going out through pix. If you customer has a vpn concentrator he could set it up to allow ipsec through tcp and that would work fine.
11-16-2002 05:34 AM
I'm definitely doing NAT.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide