07-23-2006 01:05 AM
Hello,
I need to open a site-to-site VPN between 2 PIxs v7.2.1. But on one PIX, the "private network" to be accessed via the VPN is on interface outside eth 0 (security level 0). The VPN tunnel starts from a DMZ interface, eth2 (security levl 2). So I need to apply nat 0 on interface outside, and I would like to know if it can work, because it seems strange, or if I need to change the security levels ?
Thank you,
Patrice
07-28-2006 06:33 AM
Your scenario is indeed strange. Usually, the private networks are either behind the firewall or on the DMZ segment. But I believe the PIX 7.x supports the concept of haripinning, that is the traffic received on one interface can be sent out the same interface (this was not the case with 6.x). In your case, if the routing is properly configured, the tunneled packets can be sent out the outside interface.
07-30-2006 09:34 AM
Hello,
Thank you a lot for your answer.
Patrice
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide