cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
620
Views
0
Helpful
10
Replies

RV320 to PIX 515E Tunnel

seth
Level 1
Level 1

Hello all...
I have an RV320 (internal LAN 10.78.0.0/24) connecting to a PIX 515E (10.10.0.0/24) using VPN Tunnel.
The tunnel between the two is up and working.

From my workstation (10.10.0.47), I can ping and connect to a server sitting on the RV320 LAN (10.78.0.54)

Now if I remote into the 10.78.0.54 box, I cannot ping or connect to my workstation (10.10.0.47).
I can however ping the inside interface of the PIX 515E 10.10.0.252

So what am I missing here?

1 Accepted Solution

Accepted Solutions

The LAN is 10.78.0.0/24. Make the remote VPN pool 10.78.1.0/24. Then use 10.78.0.0/23 as the encryption domain.

View solution in original post

10 Replies 10

Philip D'Ath
VIP Alumni
VIP Alumni

Probably NAT and/or an access-list rule.

Yeah you are prolly right....
I will keep looking and digging. 
See if I can find it.

Is there a way to have multiple tunnels to the same subnet on the RV320
For instance...as stated above I have the RV320 LAN (10.78.0.0/24) and Remote IP Pool for VPN Clients (192.168.5.0/24)
On my PIX I have 10.10.0.0/24
The problem I am running into is this.

I have a VPN Tunnel setup between PIX and 320 so that remote VPN Clients connecting to the RV320 have access to the LAN on the PIX, so 192.168.5.0/24 <-> 10.10.0.0/24, and the tunnel is established using the subnet option  on the RV320, not the Range option.
I also set up a tunnel for the RV320 LAN to talk with the PIX LAN so:
10.78.0.0/24 <-> 10.10.0.0/24
But with the RV320 since I already used the subnet option for the 10.10.0.0/24 LAN I cannot use it again, so I have to use the Range option 10.10.0.1 - 10.10.0.254

Now that will work sorta work....until both tunnels are being used, then all hell breaks loose....
I start loosing connectivity between the two firewalls.
The RV320 does not give me much info on the tunnels, but the PIX gives me some....
When I view the setup of the VPN Lan-to-Lan tunnels for the those two tunnels it shows
0.0.0.0 255.255.255.255 on both sides of the tunnel
Whereas on other tunnels it shows the actual LAN segments properly (I have other tunnels established to another PIX) i.e.: 10.75.0.0 255.255.0.0 on one side and 10.10.0.0 255.255.255.0 on the other side.

So that makes me think that the reason I am having issues w/ the RV320 is due to the fact that I have to use the Range option for one tunnel and the subnet option for the other tunnel, and this information isn't being passed correctly to the PIX.

Any ideas on how to correct this?

The RV320 is quite limited in this regard.

Place your VPN pool of users adjacent to the netblock for your main network, then you should be able to include both sets of IP addresses in one subnet.

Not sure I follow what you mean on that one.....
Are you saying make the pool 10.78.1.0?
I don't think the RV320 will let me do that....

The LAN is 10.78.0.0/24. Make the remote VPN pool 10.78.1.0/24. Then use 10.78.0.0/23 as the encryption domain.

Ok, I will see if I can do that

Looks like it may work.
I have a user who will test the Remote VPN Client side of things tonight and see how it goes.
Fingers Crossed.

Ok, got my tunnels up and working...
Weird issue is this.
From a server sitting on the RV320 LAN (10.78.0.54) I can ping to a server at the other end of a tunnel on a pix (10.76.50.12)
I can also do a UNC mapping to the server and browse it's C: drive
But if I try to do a RDP connection to the server it fails immediately.  The PIX Log shows a Reset I, so internal reset.

Now if I log into the the 10.76.50.12 server and RDP to 10.78.0.54, that work's fine.  No issue.
As for a security policy I have allowed all IP traffic between the two subnets to be permitted.  Rule set on the PIX.

So what am I missing?

Ok, got the RDP issue figured out.
Forgot the box that we stuck in over there never got patched to use TLS 1.x only for RDP connections...

Patch installed, connection established.
All is good.