cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
255
Views
0
Helpful
1
Replies

vpn lan-to-lan with pix behind router

jorge.sastre
Level 1
Level 1

Hello,

I'm going trying connect 2 pix in a Lan-to-Lan vpn in the next

schema:

Lan1 -- Pix1 -- Router ------- Internet --------- Pix2 --- Lan2

The problem is that between Pix1 and Router there is a private lan

and although I have redirected all traffic get by Router to Pix1

(ipsec, ip 50, 51,... included), the vpn doesn't work. Any idea?

Thanks in advance,

J.

Config: Pix1 inside: 192.168.10.1/24

Pix1 outside: 192.168.2.2/24

Router inside: 192.168.2.1/24

Router outside: Public IP 1

Pix 2 outside: Public IP 2

Pix 2 inside: 192.168.20.1/24

1 Reply 1

pkapoor
Level 3
Level 3

I suppose that the PIX1 has a NAT on the router. I also suppose you've already tried to ping between the PIXs to make sure that they can talk to each other in the first place.

You mentioned that you've allowed protocol 50 & protocol 51. Have you allowed UDP/500 port also? Important to IPSec to work. If you've opened UDP/500 and the PROTOCOLS (note that they are not port numbers) then post your PIX configurations and the router configuration as well.