Hello all,
I inherited a cisco 1700 series router. I have worked on a PIX before, is the cisco ios similar to PIX command config syntax?
Can someone point me to any info on the 1700's config syntax?
Also can the 1700 be used as a vpn endpoint?
thanks for any idea
Hello encinitas ,
A.F.A.I.K.
You would use this cfg solution foe pppoe
vpdn group pppoe_group request dialout pppoe
vpdn group pppoe_group localname username@sbcglobal.net
vpdn group pppoe_group ppp authentication pap
vpdn username username@sbcglobal.net password ********
If you have a...
julianmd,
Thanks for the idea unfortunately I get this response from the pix
Result of firewall command: "nat (inside) 0 192.169.2.0 255.255.255.0 10.10.10.0 255.255.255.0"
ERROR: invalid connection limit <10.10.10.0>
Usage: [no] nat [(<real_ifc>)] <nat-id>
{<real_ip> [<mask>]} |...
Hello bman38,
I'm no expert, but I think you will need an "access group" staement like this:
access-group <access list name> in interface outside
hope this helps
P.S.
Concerning problem 2 I get this message in the PIX error log when I get the safenet client to connect to the pix, but can't ping past the pix interface
192.169.2.1 Oct 03 2005 17:28:48: %PIX-3-305005: No translation group found for icmp src outside:141.157.58.22 dst inside:192.169.2.2...
Well here is where I am.
Quick overview of problem:
1. Using Safenet Softremote, or Cisco v 4.6 client I cannot connect to a VPN endpoint (a DLink 808 HV router)The PIX error log states that
192.169.2.1 Oct 03 2005 16:41:59: %PIX-6-302015: Built outbound UDP connection 750 for...
Thanks for the idea,
when i insert this command I get this
Result of firewall command: "nat (0) 192.169.2.0 255.255.255.0 10.10.10.0 255.255.255.0"
ERROR: invalid NAT ID <192.169.2.0>
Usage: [no] nat [(<real_ifc>)] <nat-id>
{<real_ip> [<mask>]} | {access-list <acl_name>}
[dns]...
O.K. I see,
however my set up is like this
internet (pppoe)-- (ouside interface)-- pix (inside interface)--192.169.2.1 connects to a switch
I was using the pix as a firewall & router (only one on network)
I thought the 10.10.10.0 addreses were assigned to my vpn client when they connect...
Thanks for the reply lgarner,
I am not sure what the "next hop" is.
Could you explain why you think it should be 192.168.2.2?
I thought the route stamnet would direct the vpn trafficc 10.10.01.0 to the internal netwwork 192.169.2.0
Thanks agian
Thank you for this information. I'm new to the PIX / cisco equipment.
I was going to begin locking down once I had all the functions I needed working.
Again many thanks for your time & knowledge
Hello All,
Fisrt Thanks for all the help given, it is greatly appreciated.
I can connect via vpn client to my pix, but I can't ping any internal pc's. I can ping the internal ip of the pix with no problem.
I am testing with 2 vpn clients, safenet softremote, and cisco v4.6. The cisco client...
Hello All,
I'm Backkkk....
I still need some ideas on why my PIX is not allowing my vpn client to connect with an outside endpoint.
Has anyone out there ever have this issue.
Briefly
dsl modem <===PIX<===ethernet switch<===pc w / vpn client (safenet softremote & cisco 4.6)
My vpn clients can...
Hello All,
I have a problem with packets going from my network thru the PIX to my vpn endpoint. If the PIX is off the network (just my verizon dsl modem, and a dlink switch using verizon pppoe dialup client) my safenet client connects to my endpoint fine. When the PIX is connected to the network...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.