11-21-2005 12:33 PM - edited 02-21-2020 12:32 AM
Hi all,
I have read that PIX version 7 and up allows "hairpinning" encrypted traffic. That's beautiful, but did someone find out how to route regular IP traffic through the same interface (same security level) on a PIX running version 7up? Alernatively, can we do it through a loopback interface like with IOS ?
Thanks
Simon Laurin
11-24-2005 03:28 AM
Hi,
it isn't possible with PIXs.
At this moment FWSM supports this feature (routing through the same interface), I think that Cisco will add this feature on PIXs in a near future ...
hope this helps.
Juan.
11-30-2005 09:22 AM
I have set this up for hub and spoke vpn clients and it works like a charm. I used the same-security-traffic perpit intra-interface. The key here is intra-interface which specifies ipsec traffic, if you use inter-interface it allows communication between interfaces with the same security level but you would need a seperate physical interface.....have a look at the command guide here
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_70/cmd_ref/index.htm
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide