I have several small branch offices doing site-to-site VPN tunnels. Three are doing PIX(501)-to-PIX(515) and seem to work fine.
Two are doing PIX(501)-to-3005 and have always done fine until recently.
The reason we want all the tunnels to terminate at the 3005 is because in the PIX-to-PIX scenario, we can't have Satellite1 talk to Satellite2. Each Satellite can only communicate with the hub. We'll eventually need the satellites to talk to each other, as well.
This works beautifully with the two satellites whose tunnels terminate on the 3005.
However, just recently, one of the satellite offices added a few nodes, to take them from 10 to 14, which includes the PIX, a server and four printers. There are eight users. If four or less are in the office, everything is fine. But if five or more are in the office, some can't get in. Evidently, no more than ten nodes can cross the tunnel at any time.
One of the users down there power-cycled the PIX and users could connect, but then they couldn't print (from the mainframe, located behind the 3005 at the hub). Or the server wouldn't respond (to attempts from outside the local LAN).
Locally, everything worked fine. They all had IPs and could hit the server and ping each other. They could print locally if they wanted to. They just couldn't get through the tunnel. Like it limited it to 10 connections.
I've verified that the PIX 501 we have is a 50-user, but I'm starting to wonder if it is a limitation in the number of IKE tunnels, which is limited to 10? That is the number of connections they can establish.
Thanks in advance.
Two are doing PIX(501)-to-3005 and have always done fine until recently.
The reason we want all the tunnels to terminate at the 3005 is because in the PIX-to-PIX scenario, we can't have Satellite1 talk to Satellite2. Each Satellite can only communicate with the hub. We'll eventually need the satellites to talk to each other, as well.
This works beautifully with the two satellites whose tunnels terminate on the 3005.
However, just recently, one of the satellite offices added a few nodes, to take them from 10 to 14, which includes the PIX, a server and four printers. There are eight users. If four or less are in the office, everything is fine. But if five or more are in the office, some can't get in. Evidently, no more than ten nodes can cross the tunnel at any time.
One of the users down there power-cycled the PIX and users could connect, but then they couldn't print (from the mainframe, located behind the 3005 at the hub). Or the server wouldn't respond (to attempts from outside the local LAN).
Locally, everything worked fine. They all had IPs and could hit the server and ping each other. They could print locally if they wanted to. They just couldn't get through the tunnel. Like it limited it to 10 connections.
I've verified that the PIX 501 we have is a 50-user, but I'm starting to wonder if it is a limitation in the number of IKE tunnels, which is limited to 10? That is the number of connections they can establish.
Thanks in advance.