srlenz2004
IS-IT--Management
Greetings.
Here is my problem. I have a Pix 506e using firewall version 6.3(3) and PDM version 3.0(1). I currently have 6 different private side class C's internally (192.168.x.x), each supporting one of my remote offices. I have an internal user who, at any given time, can be on any of the available class C's depending on the office she is physically at. This user needs to be able to have PPTP/VPN access to her companies VPN server outside of our firewall.
My PIX currently limits just about everything from coming in, save a few exceptions for remote management. I have only 6 total rules in place to allow for this. The problem, and maybe it's my approach as I'm trying to do this through the PDM, is in setting up a rule that allows PPTP traffic from any external address to any one of my internal class C's, and dealing with NAT and address routing on the inside.
I go into PDM, and set up a rule allowing any outside PPTP source traffic to go into my internal network, but as opposed to just being inside:any, it changes it over to a public side real IP address in the 66.x.x.x range (same range as my external interface).
Any clues as to what I'm doing wrong, or what else I should look for?
Thanks!
Here is my problem. I have a Pix 506e using firewall version 6.3(3) and PDM version 3.0(1). I currently have 6 different private side class C's internally (192.168.x.x), each supporting one of my remote offices. I have an internal user who, at any given time, can be on any of the available class C's depending on the office she is physically at. This user needs to be able to have PPTP/VPN access to her companies VPN server outside of our firewall.
My PIX currently limits just about everything from coming in, save a few exceptions for remote management. I have only 6 total rules in place to allow for this. The problem, and maybe it's my approach as I'm trying to do this through the PDM, is in setting up a rule that allows PPTP traffic from any external address to any one of my internal class C's, and dealing with NAT and address routing on the inside.
I go into PDM, and set up a rule allowing any outside PPTP source traffic to go into my internal network, but as opposed to just being inside:any, it changes it over to a public side real IP address in the 66.x.x.x range (same range as my external interface).
Any clues as to what I'm doing wrong, or what else I should look for?
Thanks!