cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
222
Views
0
Helpful
1
Replies

VPN Client-to-Client Communication using PIX 515E

afredriksson
Level 1
Level 1

Hi there!

I have a question that I believe I already know the answer to…

Our network is protected by a failover PIX 515E (6.3.4) solution and we are using Cisco VPN client (4.0.5A) to access internal networks. Split-tunnel is used to provide simultaneous intranet/internet access. We are also using Cisco IP telephony with both IP phones and softphones (Cisco Communicator). Softphones are intended to be used by people that aren’t locally connected.

Now, the question…

If I’m correct, there’s a limitation in the way vpn clients can communication through a PIX, i.e. traffic must pass through, not bounce! Is that the reason two vpn connected softphones cannot communicate? Signaling works (the phone rings) but that traffic is controlled by the IP telephony server, not the clients.

Does anyone know when Cisco intends to fix this problem?

/Anders

1 Reply 1

drolemc
Level 6
Level 6

I think the PIX is not designed to route traffic out an interface from which the traffic has been received. To allow spoke to spoke communication , you need to terminate the two Client tunnels on different interface of the PIX. For more info, you could have a look at the config example at http://cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080103ed0.shtml