Cheers Roland - i will try this tonight.
Appologies for not getting back to you sooner. Just got back from Greece ;) but it was for business :(
Will let you know how i get on!
Hi Rowland
Does this Split tunneling mean the teleworker (end of VPN) can use there own internet connection to browse the internet but use the VPN to access company data!
If it does that sounds the trick! Do i need config at the users end and also the pix end???
Hi,
Would you like to help me on my VPN Cisco Headache? Or are you still putting your feet up ;)
No worries if your to busy because you done me a massive favour already!
But anyway heres my new thread thread35-1112670
Thank you once again
Hi All,
I need some help to setup 3 VPN connections.
I have a Cisco PIX 506E configured and working as a Firewall only. I need to setup the VPN connections.
What I am Replacing
My current VPN concentrator which i am replacing with my PIX uses a presharred key with 3DES/MD5.
My current VPN...
dopehead correct
The PIX Factory Default IP address and path for PDM is Https://192.16.1.1/startup.html
If you are trying to config the PIX on a different network than 192.16.1.0 you will have to add the following commands using the IOS
(in enabled, and config t)
no http 192.168.1.1...
Hi kam72,
I Have just configured my first PIX this week with some great advise from some of the members on this site, so i am going to pass on the goodwill.
The PDM software is great for monitoring the Firewall but i found it really tricky to configure it. I would really recommend that you...
It works! all the rules are working really well
Thank you so so much!
Will i have to add any more rules for when i setup VPN access for users to gain full unrestricted access to our LAN?
Are you interested in helping me setup the VPN connections? Or do you want a break and put your feet up...
using the PDM to look at the config. The PDM ignors the following commands;
access-list 100 permit icmp any host 76.100.66.66 echo-reply
access-list 100 permit icmp any any time-exceeded
access-list 100 permit tcp host 223.253.45.146 host 76.100.66.66 range ftp ssh
access-list 100 permit...
cheers rowland
ok i cant recieve emails from external sources, but i can send them out of our network.
I cannot ping, tracert etc... devices outside my network
I havent checked whether our sister company can gain access but will be doing that tonight.
Part from that everything else works ;)...
Well i tried the config and it didn't work! Maybe i will try it without the static route!
p.s. i will try it again... then i will paste my config. Got any thoughts?
p.p.s. Does you job get you angry when you cant do any changes in office hours! i hate working late!
and when this is sorted i will only have to setup up my VPN connections. Another CISCO Headache!!!
Oh CCSP - Canadian Centre for Studies in Publishing i see ;)
Will try this over the weekend when all the staff have gone home, because they will only moan. So i will let you know on Monday if it is ok!
What about allowing port 25 (SMPT) from my easynet relays? Do you know how to allow this? Do i need another static route (hope not).
EasyNet Email...
thanks for getting back.... that looks what i needed!
However when i try to input:
access-list 100 permit tcp host 223.253.45.146 interface range 21 22
It Returns:
interface <range> does not exist
Usage: [no] access-list compiled
[no] access-list deny-flow-max <n>
[no] access-list...
Also why do i need to create the static mapping below?? and another IP address?? What does the Public IP address do?
Your SMTP traffic will send from address 76.100.66.Y on port 25--as long as your server is configured correctly.
**You need to use yet another Public IP for this one call it...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.