05-15-2006 01:31 PM - edited 02-21-2020 02:24 PM
Hi,
I was wondering if anyone has tried implementing IPSec VPNs to a VLANed interface. I have 2 DSL connections each with only on static address. I want to pass them through a Cisco router, NAT them, and then forward the IPSec request to one of 2 Logical (VLAN) interfaces on the outside interface of the PIX. Is this something that will work?
Kelvin
05-19-2006 10:56 AM
05-20-2006 02:41 PM
You mean .. you have your PIX outside interface connected to a switch as trunk. You have 2 VLANs linked to the outside interface. You have your VLANs interfaces NATed on the router to public addresses. You want to terminate the Ipsec on one of the VLANs .. Am I correct ..
If this is the case then it should be OK .. just make sure the PIX and router can pass IPsec and also make sure your PIX allows NAT-Traversal. The device at the other end also needs to support nat traversal.
isakmp nat-traversal 20
I hope it helps ... please rate if it does !!!
05-25-2006 07:18 AM
Hi guys thanks for the reply, I actually got a PIX in house this evening so I will be upgrading the PIX 7.0(4) to 7.1 and then simulating the environment here at my office. I will let you know what happens over the next day or so.
Kelvin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide