cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
239
Views
0
Helpful
2
Replies

VPN Client to PIX through PIX

harvey.dewan
Level 1
Level 1

I have a user from another company that needs to access his Company VPN, which is a PIX. He is having to go through our PIX to do it. I only have 1 IP at the site in question (its DSL). Can this be done.

Thanks

2 Replies 2

ehirsel
Level 6
Level 6

I don't believe so, since you only have one (public) address the pix will get confused with the esp traffic thinking that it directed to it instead of the client behind it.

I would contact the other company's vpn/firewall admin and see if you can setup a site-to-site vpn between your pix and the other one.

scoclayton
Level 7
Level 7

Actually, you can accomplish this for a single internal VPN client by using a new feature in the PIX 6.3 code - http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63rnotes/pixrn63.htm#67762

Another option would be to have the other side configure VPN Nat-Traversal if they are running 6.3 code as well - http://www.cisco.com/en/US/products/sw/secursw/ps2120/prod_release_note09186a00801a6d21.html#65230

Hope this helps.

Scott