12-14-2005 08:17 AM
I have a private network address at home of 192.168.4.0 which i use to connect to my office vpn. VPN is setup on a pix 515 at the office using version 634. The inside network address on the pix is 192.168.2.0. The vpn client address is 192.168.1.0. I can connect to the inside network fine but i can't connect to another subnet that is directly connected to the pix for example the dmz. The dmz address is 192.168.3.0. I trying to use both terminal server and realvnc. When i am working at the office i can connect to this subnet using terminal server and realvnc but i can't connect nor ping these devices from home. I am not sure if i am missing something. Any help will be greatly appreciated.
Thanks in advance
12-14-2005 04:02 PM
In your PIX you'll have commands someting like the following:
access-list nonat permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
nat (inside) 0 access-list nonat
This tells the PIX that any traffic coming into the inside interface and destined for your VPN client should not be NAT'd. You need to do a similar thing for access to the DMZ network, so add lines like such:
access-list nonatdmz permit ip 192.168.3.0 255.255.255.0 192.168.1.0 255.255.255.0
nat (dmz) 0 access-list nonatdmz
and you should be able to access hosts on the dmz interface from a VPN connection.
12-15-2005 05:44 AM
I will add those commands and when i go home this afternoon i will test it. Your explanation was very clear.
Thanks,
Lake
12-16-2005 03:04 PM
It didn't work. I double check the commands i entered. I will have to do some more checking. Thanks a lot for your help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide