Cisco Systems Is this possible : VPN Configuration

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Is this possible : VPN Configuration Stewart 04-28-06
Posted by Stewart on April 28, 2006, 12:26 am
Please log in for more thread options
I have 3 PIX 501 firewalls running PPOE ADSL connections.

Head Office
2 * Remote locations

We need to extend the configuration to include some VPN features:

Office
PAT (I think this is the term) - external inbound connections (eg port
80 443 5060 etc) - WORKING
Software VPNClient will connect to this point (users travelling need to
access the office network) - WORKING
Hardware VPN Host (Server)
Radius SERVER authentication for software VPN clients - WORKING
Provides primary internet connection for this location

Remote1
PAT (I think this is the term) - external inbound connections (eg port
80 443 5060 etc) - WORKING
Software VPNClient will connect to this point (users travelling need to
access the office network)
Hardware VPN will connect to Office - needs to be in NEM mode - both
sides should be able to see resources on both sides
Provides primary internet connection for this location - this means we
need split tunnel for the VPN connection???

Remote2
Software VPNClient will connect to this point (I believe that users in
remote1 location would need to do this to access resources in this
location?)
Hardware VPN will connect to Office - needs to be in NEM mode - both
sides should be able to see resources on both sides
No external internet access required here

Is this possible? I have read a range of materials much of which is
confusing for the inexperienced. Some of the items concerning me are

PAT cant be done whilst the Hardware vpn is configured?
Software and Hardware VPN hosts (servers) cant coexist on same device
Remote1 cant route to Remote2 (in out not allowed rule on one interface???)

Where do I go to start to get a working config for this?

How does the addressing work on the internal networks?

At the moment I have PPOE connection going ok and the inbound PAT stuff
working with software VPN authenticating against a separate RADIUS server.
We have successfully connected (I think) from Remote1 to Office with
hardware vpn but Office then lost all internet access.

Thanks

Stewart



Similar ThreadsPosted
Configuration reverted to previous configuration after power loss March 3, 2006, 11:14 am
PEAP Configuration Woes - PEAP configuration help December 19, 2005, 3:41 pm
Is this possible : VPN Configuration April 28, 2006, 12:26 am
PIX and BGP Configuration June 5, 2006, 5:17 pm
PIX 501 VPN Configuration June 9, 2006, 12:01 am
VPN Configuration August 18, 2006, 10:59 am
PIX Configuration Help ! August 28, 2006, 11:58 am
T1/E1 and T3/E3 - configuration September 11, 2006, 4:58 am
ssh configuration September 17, 2006, 6:39 pm
ASA Configuration September 27, 2006, 10:37 am
Configuration Example October 14, 2006, 3:57 pm
851 configuration November 2, 2006, 4:55 pm
PIX 501 DSL Configuration November 21, 2007, 1:42 pm
Pix 501 Configuration November 22, 2007, 10:01 pm
Policer configuration July 22, 2005, 1:54 am