11-30-2006 04:51 AM
Hi Friends,
Can we make another interface as inside other than ethernet1, by the configuring security levels of interface.?
Thanks in advace.
Kamal
kashyap_kamal@rediffmail.com (pls reply on this email id)
11-30-2006 07:13 AM
Hello Kashyap,
Yes, you can use other ethernet interfaces as an inside interface and change the security levels. That should not be an issue at all.
Rate this topic, if it helps.
Cheers
Gilbert
11-30-2006 11:49 PM
Hello Gilbert,
I configured the new interface with same security level of 100 as inside interface.
Everything works fine except the VPN tunnels.
And after wards reverted back to pervious configuration and found the VPN tunnels working fine.
My point of concern is do VPN Ipsec tunnels get affected after changing the inside interface to other physical interface.
Thanks!
Kamal
12-01-2006 07:15 AM
Kamal,
Can you please let me know what changes were made on the PIX. And a snippet of the changes made would be helpful.
VPN traffic should not be affected.
1. After the change, did you see the tunnels on the PIX.
sh cry isa sa - would show that to you.
2. Did see packets decrypted on the PIX -
sh cry ipsec sa - would show you that.
3. What was your "nat" statement like, after the change?
Please let me know.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide