cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
412
Views
0
Helpful
3
Replies

VPN Client behind PIX connecting to remote PIX

markwood
Level 1
Level 1

Scenario: Two companies both behind PIX firewalls. Company A uses the Cisco VPN client to connect to the Company B network from a single PC (behind the Company A firewall). This works and the client can access the necessary servers. Company A also has mobile clients that use Cisco VPN client connections from home to connect to its own (Company A) network which they can do successfully.

Company B is trying to use the Cisco VPN client to connect to the Company A network from a single PC (behind Company B firewall). Company B manages to connect to the network succesfully, but it unable to access any resources and cannot ping any destinations on the Company A network.

I have tested the VPN client configuration Company B was given using a dial up Internet link with no problems.

Any ideas why this problem might be occuring?

Many thanks

Mark

3 Replies 3

mostiguy
Level 6
Level 6

is company b filtering outgoing traffic?

llascare
Level 1
Level 1

Make sure Company A's PIX is running software version 6.3 and add the "isakmp nat-traversal" command. If this doesn't work, then try to create a static translation for the PC behind Company B, on company B's PIX, so that the VPN client can connect using a non-PATted IP address.

Also make sure you have

sysopt connection permit-ipsec

on the other pix as it is probably already on pixA