Forums before death by AOL, social media and spammers... "We can't have nice things"
|    comp.dcom.vpn    |    VPN protocols, clients, awesomeness    |    2,348 messages    |
[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]
|    Message 786 of 2,348    |
|    Unnar Gardarsson to Martin Eden    |
|    Re: pix to pix filter traffic    |
|    07 Feb 04 19:07:19    |
      From: unnar@cox.net              Do you have a line in your PIX that says "sysopt connection permit ipsec"?              If so you need to remove it and just specify in your inbound access-list       what you want the network behind pix2 to access, ie.              access-list 100 permit tcp 172.30.1.0 255.255.255.0 host 192.168.1.a eq xxx       access-list 100 permit tcp 172.30.1.0 255.255.255.0 host 192.168.1.b eq xxx       access-list 100 permit tcp 172.30.1.0 255.255.255.0 host 192.168.1.c eq xxx              As long as you know what port numbers the remote site needs to access, it       should be a piece of cake.              sysopt connection permit ipsec, basically tells the pix to ignore filters       when the traffic is coming over a VPN connection..              Hope this helps              Unnar              "Martin Eden" |
[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]
(c) 1994, bbs@darkrealms.ca