VPN with PIX (IPSEC)

Oct 19, 2009 4 Replies

Hello All,



I have a PIX 515 that's configured as a VPN IPSEC provider, amongst other things. When establishing a tunnel, everything goes fine but the VPN machine isn't able to ping anything inside. The log is showing something like



305005: No translation group found for icmp src outside:192.168.10.2 dst inside:192.168.2.11 (type 8, code 0)

whereby 192.168.10.2 is the VPN IP address.



What's going wrong here ? Do I need nat/global or static entry for the VPNed network, especially given that they seem to be on the outside interface ? Many thanks for your help in advance !



Best wishes



hi

u need no nat in the interface outside and maybe routing.

cheers

yes, you need a nat 0 and create an access-list for what you dont want to be translated to the outside address when traversing VPN.

a static will work as well.

Hi:

Is the PIX 515E-R firewall still a reasonable choice as a stateful firewall? I know it is a discontinued item from Cisco but from what I have read from old reviews, it was a very good when it came out.

Any comments would be useful.

Thanks - Kevin

Absolutely! The downside is cisco is no longer making software. Just keep an eye out for vulnerabilities in your version and determine if their risk is to high. Then when you have the budget for an ASA pick it up

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required