05-24-2005 07:09 AM
Hello everyone,
I have an interesting problem to submit.
I have a PIX 515E with 3 interfaces (outside, dmz, inside). I have a working VPN configuration with a site-to-site tunnel to another office and remote clients connecting from home, to the network on the inside interface. On the DMZ interface, I have another network, actually a test environement, that cannot, in any case, be connected to my corporate network. What I want to do is access this test network by connecting with a VPN client.
Now, here's the question: Is it possible to have two different VPN configurations for remote clients, one for clients connecting to the corporate network, and the other for the people connecting to the test environement?
If someone has already tested this config, it would really help me.
Thanks
Antoine
05-31-2005 06:47 AM
I think the document "Configuring the Cisco VPN Client to Tunnel to Two Remote Sites Through One Hub PIX" could provide you with some useful information.
http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080103ed0.shtml
05-31-2005 03:49 PM
It sounds to me like what you really want to do is add another entry to the crypto map. Just have it use a different "group" or different certificates if that is how you setup your vpn. Then, you can set up a completely different ACL which allows VPN into the test network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide