cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
426
Views
0
Helpful
4
Replies

VPN Tunnel Between Pix & Router

Mohamed Sobair
Level 7
Level 7

Guys,

I would like to setup basic VPN tunnel between a router and other pixfirewal, what should I keep in concern? also could any body show me sample config that shoud be done on Pix?

thanks,

4 Replies 4

mheusinger
Level 10
Level 10

Hello,

this should not be too difficult in case you follow

"Configuring IPSec - Router to PIX" at

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094498.shtml

and have the proper IOS versions.

Another option using certificates:

"How to Configure a LAN-to-LAN IPSec Between a Router and a PIX Using Digital Certificates"

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800946c0.shtml

Hope this helps! Please rate all posts.

Regards, Martin

Hi Martin,

Thanks for ur input, but I am not sure that I got fully understand the bellow when reading the above link:

This document illustrates an IP Security (IPSec) configuration between a router and a Cisco Secure PIX Firewall. We want to use private internal IP addresses when passing traffic between the headquarters LAN and the remote LANs, and to translate the LAN hosts to routable IP addresses when users access the Internet. However, users can also access public pages on the Internet without their traffic going through the tunnel using the route-map command.

could u clarify it a little bit more,

Thanks,

Hello,

LAN users behind the router can access the LAN/networks behind the PIX through the IPSec tunnel. In addition internet access is allowed locally and not through the HQ. Wen the internet is accessed through the router locally, the router will also perform NAT to allow this.

Hope this clarifies a bit. What is still unclear?

Please rate all posts. Regards, Martin

Hi Martin,

u clarify it quite well, but I have one question:

1- What if I want to use all internet services/access via the HO, I meant to say in my case, I would like users behind the router using (proxy settings/Internet access/ip telephon communications) thats already applied behind HO-PIX?

In other words, lets consider the HO here is more likely provider, could I use all the Services including Internet access through the IP Sec Tunnel?

Thanks a gain for your concern,

Mohamed,