cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
517
Views
0
Helpful
2
Replies

VPN tunnels simultaneously to DMZ and to inside

amaitre
Level 1
Level 1

Hello everyone,

I have an interesting problem to submit.

I have a PIX 515E with 3 interfaces (outside, dmz, inside). I have a working VPN configuration with a site-to-site tunnel to another office and remote clients connecting from home, to the network on the inside interface. On the DMZ interface, I have another network, actually a test environement, that cannot, in any case, be connected to my corporate network. What I want to do is access this test network by connecting with a VPN client.

Now, here's the question: Is it possible to have two different VPN configurations for remote clients, one for clients connecting to the corporate network, and the other for the people connecting to the test environement?

If someone has already tested this config, it would really help me.

Thanks

Antoine

2 Replies 2

didyap
Level 6
Level 6

I think the document "Configuring the Cisco VPN Client to Tunnel to Two Remote Sites Through One Hub PIX" could provide you with some useful information.

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080103ed0.shtml

justindd1
Level 1
Level 1

It sounds to me like what you really want to do is add another entry to the crypto map. Just have it use a different "group" or different certificates if that is how you setup your vpn. Then, you can set up a completely different ACL which allows VPN into the test network.