cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
547
Views
0
Helpful
1
Replies

VPN access

Shobith K
Level 1
Level 1

In this scenario customer has a PIX firewall and LAN inside. After firewall there is a cisco router with two WAN interfaces, one going to internet and other is IPLC to US LAN.

We have set up VPN on PIX firewall for the internet users to access the INDIA LAN with the VPN Client sofware. It is working also,,

But is there any option that Clients connected through vpn able to access the US lan which is outside the firewall.??

1 Reply 1

thisisshanky
Level 11
Level 11

PIX does not allow packets arriving on a particular interface to be routed back the same interface. For the same reason it wont let you access the US Lan, though the router that terminates the connection the US lan is outside the firewall. If the VPN terminates on a router instead of a pix, the router will let you access the US Lan without any issues. I hear a rumour that with Pix OS 7.0 this limitation is getting resolved.

I had setup something similar for a customer in a round about way. On the ethernet side of the router connecting to the internet I created two subinterfaces and put them in vlan 10 and 20. PIX firewalls outside interface is in vlan 10 and PIX firewalls DMZ interface is in vlan 20. Any incoming VPN client connection from the Internet is terminated on the DMZ interface. Now the clients will be able to go from DMZ to the Outside interface without any problems. You could setup something similar so that VPN clients terminate on a DMZ on the PIX and then they go from the DMZ to Outside interface of PIX and then to the router which terminates the WAN connection to the US LAN.

Internet---Router---Vlan10---Outside--PIX--Inside

*************|------Vlan20---DMZ-------|*********

OR

In your case, you can set up a DMZ interface on the PIX and move the US WAN router to the DMZ. This way VPN users can access the US WAN by specifying access-lists or conduits on the PIX firewall.

Sankar Nair
UC Solutions Architect
Pacific Northwest | CDW
CCIE Collaboration #17135 Emeritus