cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
660
Views
0
Helpful
1
Replies

VPN 3005 behind PIX

davex316
Level 1
Level 1

I have just read in MCNS book, that the VPN 3005 should be placed behind the pix. Does everyone agree, it seem to make sense to me. Question, what do I need to allow through the PIX to allow the

IPSEC to go thruogh it.

1 Reply 1

murabi
Level 4
Level 4

Shouldn’t be too hard, just setup a static translation to the 3000 tunnel endpoint and conduits allowing ipsec traffic through to it.

For example:

static (inside,outside) 199.199.199.154 10.19.19.154 netmask 255.255.255.255

conduit permit ip host 199.199.199.154 any