cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
298
Views
0
Helpful
2
Replies

VPN Design question

p.tavan
Level 1
Level 1

Hello,

I need to open a site-to-site VPN between 2 PIxs v7.2.1. But on one PIX, the "private network" to be accessed via the VPN is on interface outside eth 0 (security level 0). The VPN tunnel starts from a DMZ interface, eth2 (security levl 2). So I need to apply nat 0 on interface outside, and I would like to know if it can work, because it seems strange, or if I need to change the security levels ?

Thank you,

Patrice

2 Replies 2

vmoopeung
Level 5
Level 5

Your scenario is indeed strange. Usually, the private networks are either behind the firewall or on the DMZ segment. But I believe the PIX 7.x supports the concept of haripinning, that is the traffic received on one interface can be sent out the same interface (this was not the case with 6.x). In your case, if the routing is properly configured, the tunneled packets can be sent out the outside interface.

Hello,

Thank you a lot for your answer.

Patrice