Two PIX + router networking

My network:

SiteA (PIX506E) -- > Site B( PIX 515E + RouterB ) --- > Router C

The Network between Site A + Site B = PIX VPN tunnel The Network between Site B + Site C = IPLC

How can I configure teh PIX so that User Site A users can access the network resources in Site C ?

Thank you so much Benson

Reply to
bensonlei
Loading thread data ...

:My network:

:SiteA (PIX506E) -- > Site B( PIX 515E + RouterB ) --- > Router C

:The Network between Site A + Site B = PIX VPN tunnel :The Network between Site B + Site C = IPLC

IPLC? International Private Leased Circuit?

:How can I configure teh PIX so that User Site A users can access the :network resources in Site C ?

Figure out the IP addresses of the resources on Site C as known to Site C. Now, add those IP addresses to the crypto map match address ACL that forms the VPN, and add them to the nat 0 access-list ACL that turns off NAT'ing for the VPN.

Reply to
Walter Roberson

Thank you so much for your reply,

Yes, the network SiteB + SiteC is an IPLC Line.

at SiteC, the IP address = 172.28.0.0 /16 at SiteB, the IP address = 172.27.0.0 / 16 at SiteA, the IP address = 172.27.28.0/24

Users at sitA can access the resources in SiteB without problem, but they can not go to SiteC

When I triedt to ping Site C subnets from Site A, there is no reply like the following result:

( by using Ethereal ) Source Destination Protocol Info

172.27.28.55 172.28.0.11 ICMP Echo (ping) Request repeat..

So, no Echo(ping)reply...Do you know what the problem is ?

On the other side, by using "tracert", always timeout....

I also tried to add all IP subnets to the NAT0...and teh VPN ACL..but in vain.

So, need your help..

Thank you Benson

Reply to
bensonlei

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.