Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I have numerous working IPSec VPNs on a PIX 515E. Once of those works a bit slow. The engineer at the remote end changed his MTU size to handle the outbound fragmentation and the performance increased a little. He wants me to change my side as well. ...
You can have different IP schemes. The only requirement is that the routing should be in place. Just to make sure you dont have any issue with DNS and ADS, go to Active Directory/Sites and Services...Add a new Site (remote site) and also drill downt ...
Since you said, all three HQ sites are connected using high bandwidth lines, I assumed the acl has the IPs of all three sites in it as destinations.... As of the peers, its goes in order of config....It goes to the next one if the previous peer is n...
You mentioned that you cant route 10.x.x.x into a VPN cos there is no VPN interface created....I think I understand what you need. Altough, there is no seperate VPN interface, you can just route the traffic towards the interface where the ipsec tunne...
By default, "address" is set as the identity. Hence it would not showup in any configs, Unless you manually add the statement again. But if you want to verify, you can launch the webbased PDM (Pix device Manager) and go to Configuration/VPN/IKE polic...