cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
616
Views
0
Helpful
3
Replies

Remote admin of a PIX running as VPN client

mikkle
Level 1
Level 1

Hi there,

I have a setup where a PIX501 works as a VPN-client up against my central VPN3000 concentrator (LAN-2-LAN mode with NAT-T).

The pix's outside interface is behind an ISP-managed firewall at the remote end, and it obtains it IP-address via DHCP.

So far so good. This setup works briliantly.

The problem is, that I can't ssh/telnet to the PIX's outside interface because of this setup.

Would it be possible to ssh/telnet to the remote pix's _inside_ interface?

I imagine some bidir NAT stuff, but I can't get it to work.

Any ideas?

:O) Mikkle

1 Accepted Solution

Accepted Solutions

ciscoacs
Level 1
Level 1

this is possible by the commands:

management-access inside

this works fine as i have used it as long as inside interface is included in all crypto config

sam

View solution in original post

3 Replies 3

mostiguy
Level 6
Level 6

what do you have for ssh statements on the remote pix? generally the outside ip of the firewall is not included in the crypto map statements, so its traffic is not tunnelled.

ciscoacs
Level 1
Level 1

this is possible by the commands:

management-access inside

this works fine as i have used it as long as inside interface is included in all crypto config

sam

You're right, it works!

That was the missing command.

Cheers!

:O) Mikkle