cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
814
Views
0
Helpful
6
Replies

little issue with pix

zulqurnain
Level 3
Level 3

i ve a case on which i seems to be a little bit lost. maybe you experts can help me solving it. by the way i am attaching the diagram for more clarity of the situtation.

we have one company say 1st company connecting to us through the internet cloud using VPN tunnel and 've access to some of our servers, till this part everything seems alright and working.

The part where it became confusing is that now this 1st company will access to another company which is connected to our network through another line.

This 2nd company has it's own network of course and question is how do i configure on the pix that if packets coming in from 1st company for 2nd company should go to this router instead of else where.

hope it is clear. any question please do ask.

6 Replies 6

Fernando_Meza
Level 7
Level 7

Hi .. posting the diagram would help . and also the VPN configuration on your pix.

Hello,

sorry i forgot to post the diagram in my first post. anyways here you go.

Salam Zulqurnain,

What you need to do is make another VPN tunnel on 2nd company's router terminating on your HO PIX and enable communication between different VPN peers on the PIX. The command on the PIX is (same-security-traffic permit intra-interface). For more information, look at (hairpinning) concept!

Regards,

Salam Zulqurnain,

What you need to do is make another VPN tunnel on 2nd company's router terminating on your HO PIX and enable communication between different VPN peers on the PIX. The command on the PIX is (same-security-traffic permit intra-interface). For more information, look at (hairpinning) concept!

Please vote if this helps!

Regards,

actually my 2nd company router is connecting with HO through a dedicated leased line and the communication is between successfully,

now what i am understanding from you is that i need to setup VPN Tunnel on our HO router connecting to 2nd company router and on my pix which is towards the internet side have to enable this command. am i right, anyways, a little for clarification would be great.

Yes, you got the idea correctly... the command which I've included allows communication between VPN spokes once the tunnel is established.

There is an example on Cisco site, If you are interested, visit the following URL:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00804675ac.shtml

Please vote for me if this is helpful!

Review Cisco Networking for a $25 gift card