-----------------------
Add configuration commands similar to those used for the inside network and vpn:
* Add a nat 0 statement with additional access-list to the dmz interface.
* Add the dmz network to the access-lists that specify the vpn traffic (bound to crypto map) and to "split-tunnel".
-----------------------
Yizhar,
Can you explain a little bit more in detail the steps to allow a VPN client to access the DMZ. I have beat myself to death over this. I'm having the problem of not being able to get to the DMZ from VPN. I'm using a PPTP connection with the standard Microsoft Client on XP.
Based on my settings:
Inside 192.168.3.0
DMZ 192.168.2.0
Outside (only temp for test lab) 192.168.1.0
VPN ip pool- 192.168.3.225-192.168.3.235
I get VPN'ed fine and can access all the Inside servers. However, I just can't get to the DMZ segment that has our webservers.
I've come to 2 conclusions:
1-my local machine doesn't know where to route when i request a DMZ address (requesting 192.168.2.0)
or
2-my access-list is screwed up somehow that's not letting vpn traffic over to the dmz.
If you want, I will post my config.
I appreciate any help you can give me.
Thanks,
Chris