site to site VPN CISCO PIX

May 01, 2006 1 Replies

I use a VPN site to site, PIX 515 to PIX 501. The access is 2 ways. Could I configure a priority through tunnel? I want to permit the access only PIX 515 to PIX 501 and deny for PIX 501 to 515.



I used crypto map outside_map client configuration address initiate --for PIX



515 crypto map outside_map client configuration address respond --for PIX
501

But I have access in two ways !!!



Could I use a command crypto ? Thank you ! silviumed



If you were to upgrade the PIX 515 to PIX 7.0 or PIX 7.1, you -might- be able to use different priorities for traffic (there is more funky new stuff in there than I can keep track of). But the 501 doesn't support PIX 7.0 or PIX 7.1. And priorities aren't the answer anyhow.

As I said in response to your earlier posting with very nearly the same wording: NO, not unless you are prepared to lose all responses including the TCP 3-way handshake.

initiate and respond have NOTHING to do with traffic control. They have to do with which system hands out the IP addresses for the link. As you are doing a site-to-site VPN, you probably don't want -either- system handing out IPs for the link.

No.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required