Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Tunnel i/f with PIX 6.3

Status
Not open for further replies.

sghezzi

Technical User
Apr 7, 2003
56
DE
Hello,

we have PIX 6.3 and we would like to use it for VPN only with double IP address on the external i/f, to connect with remote sites through two ISPs.

I think this should be possible with 6.3 because of VLANs, but I was wondering if it is also possible to have dinamyc routing between these two different paths (ISPs).
On router this is accomplished via OSPF, GRE protocol and Tunnel i/f.

Is this also possible with PIX 6.3?

If it is not possible, does it make sense to use two different i/f on PIX, give hem the same security level and then use OSPF between them?

Thanks
Silvia
 
Only problem with using VLAN on the outside is, that it is dot1q trunking, so the port must go to one router/layer3 switch in order to use 2 different ips on the outside segment, which will create a single point of failure. Not a problem, just a consideration.

You could use two different interfaces, if you only wan't GRE with OSPF in it to go through, you don't even need routing on the outside, you just need to terminate the VPN on two different adresses in the other end, and then only route the peer through the two different interfaces.

Jan
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top