Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Site-to-Site VPN, Concentrator to PIX

Status
Not open for further replies.

sohtnax

IS-IT--Management
Apr 24, 2003
130
US

I need to access resources on a remote network using a site-to-site VPN, using my Cisco VPN concentrator to connect to a remote PIX firewall.
Assuming the tunnel is established between the two devices, how would I be able to direct traffic intended for a resource on that remote site to through my VPN?
I realize I could drop a router in front of my firewall and concentrator, to appropriately rout the traffic, but I do not have a spare router at this time.


 
When you configure the VPN tunnel you define the traffic that will be encrypted and tunneled (interesting traffic), the remote resource should be defined as interesting traffic on the VPN configuration. Traffic from your network destined for the remote resource should reach your VPN 3000 which will send it through the tunnel. This means you need to have a route on your internal network saying "packets destined for the remote resource send them to the VPN concentrator". Hope this helps!
 
Thanks for you post, but I realize this. To clarify my question, is there any way to do so without using a router? For example, is it possible to use a Cisco VPN client internally and point it to my own concetrator for this site-to-site?
 
If you are planning a site-to-site tunnel then you must direct interesting traffic to the VPN 3000. How are you planning to send traffic from your network through the tunnel? How will the packets reach the VPN cocentrator in order to be encrypted?

If you want to use the VPN client, then you can configure the remote PIX for remote VPN access and terminate the tunnel at the PIX.
 
TheMut, in stating the following, How are you planning to send traffic from your network through the tunnel? How will the packets reach the VPN cocentrator in order to be encrypted?", you are basically rewording my exact question.
 
Let me put it differently, do you have a default gateway on your network? If so, what device is it? If not, how do you get to the Internet on your network?
 
The default gateway on my network for Internet access is my firewall.
 
Can you use the firewall to route traffic to the private interface on the VPN concentrator?
If your firewall is a PIX unit then it is not possible yet, but it will be possible on the soon to be released PIX version 7.0.
 
That was the answer to my question. Thanks!!!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top