cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
304
Views
0
Helpful
1
Replies

VPN on another interface (without outside )

JACKY NIGLIO
Level 1
Level 1

Hello,

it's possible to create a VPN access on PIx 6.3.3 ( not a outside interface ) to another interface ( int VPN security 1 )

With another subnet on my outside network .

thanks

1 Reply 1

ehirsel
Level 6
Level 6

Yes, you can enable IPSec vpn access on any interface, and it can also be enabled on more than one. IPSec can be used for inbound and outbound access.

With L2TP and PPTP, you can only enable it on one interface and it will accept inbound connections only.

You will need a seperate subnet for the other interface, that is unique from the inside and outside subnets.

What you will not be able to do, is to run a vpn session from a client off of the outside or inside interface, and terminate the sesiion on the VPN interface. The pix won't be able to do the "routing within the box" to handle that. So the clients (either RAS or device) will need to be routable off of the VPN interface to terminate the vpn at the pix on that VPN interface.

Let me know if this helps.