Virtual Private Networks site to site VPN CISCO PIX

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
site to site VPN CISCO PIX silviumed 05-01-06
Posted by on May 1, 2006, 7:07 pm
Please log in for more thread options
Hello all,

I use a VPN site to site, PIX 515 to PIX 501. The access is 2 ways.
Could I configure a priority through tunnel? I want to permit the
access only from PIX 515 to PIX 501 and deny from PIX 501 to 515.

I used
crypto map outside_map client configuration address initiate --for PIX
515
crypto map outside_map client configuration address respond --for PIX
501

But I have access in two ways !!!

Could I use a command crypto ?
Thank you !
silviumed


Posted by Walter Roberson on May 2, 2006, 1:09 am
Please log in for more thread options
>I use a VPN site to site, PIX 515 to PIX 501. The access is 2 ways.
>Could I configure a priority through tunnel? I want to permit the
>access only from PIX 515 to PIX 501 and deny from PIX 501 to 515.

As I answered to your posting in comp.dcom.sys.cisco, you can't do
that -- not unless you are prepared to forgo -all- responses
(e.g., not even allow a TCP SYN ACK get through.)

If you just don't want to be able initiate new connections from
the 501 to the 515, follow the guidelines of my other reply.

Posted by Vikas on May 24, 2006, 7:39 am
Please log in for more thread options
Hello Siliviumed,

Try removing the acl entry pointing towards PIX515 from 501 in nonat.

-Vikas


Similar ThreadsPosted
Cisco Site to Site VPN. Is it possible to join domain over VPN connection? October 8, 2007, 7:09 pm
Aweful Cisco site to Site vpn - outlook 2003 November 11, 2007, 5:28 pm
cisco 1811 looses connectivity ( site to site vpn ) November 16, 2007, 8:34 pm
How to Configure Site-to-Site VPN in Cisco Routers May 2, 2007, 5:31 am
site to site VPN CISCO PIX May 1, 2006, 7:07 pm
Checpoint VPN Edge to Linksys BEFVP41 site to site February 15, 2005, 10:32 am
Sonicwall Site to Site VPNand Active Directory March 24, 2005, 2:42 pm
REQ: Low-end site-to-site VPN router that does split tunneling October 13, 2005, 10:53 pm
RV042 / SSG-5 site-to-site Advice Needed November 20, 2007, 10:49 am
VPN site to site explanation needed June 15, 2005, 7:31 pm
Setting up site to site VPNs February 25, 2006, 3:10 pm
Linux Site to Site Private May 8, 2006, 1:07 am
Site to site VPN - when VPN is up, web access fails January 18, 2007, 6:32 am
Site-tp-site VPN over ADSL to G.SHDSL January 22, 2007, 3:31 pm
Setting up site to site VPN with RV042s April 21, 2007, 2:21 pm