|
|
Pix to Pix: Initiate VPN on one side only...
I have established VPN connection from one Pix 506 to several Pix 501 for
server admin purposes. However, I do not want it to be possible to
initiate/establish the tunnels from the 501s, ie. it should not be possible
for the users out there to establish tunnels...
How do I do this? Preferably, is there a neat way to fix this in the PDM
(3.0(1)?
BG
|
|
0
|
|
|
|
Reply
|
BG
|
11/17/2003 10:40:55 AM |
|
In article <3B1ub.7178$mf2.99596@news4.e.nsc.no>,
BG <young_neils@hotmail.com> wrote:
:I have established VPN connection from one Pix 506 to several Pix 501 for
:server admin purposes. However, I do not want it to be possible to
:initiate/establish the tunnels from the 501s, ie. it should not be possible
:for the users out there to establish tunnels...
:How do I do this? Preferably, is there a neat way to fix this in the PDM
:(3.0(1)?
I haven't used PDM very much at all, so I don't know how it would be
done at that level.
The strategy to use is to create standard 'crypto map' on the 506,
but on the 501's, instead use 'crypto dynamic-map'. You can't
initiate a connection outwards via a dynamic map because it doesn't
know the peer to connect to.
At the CLI level, setting up a dynamic map is not much different
than setting up a standard map.
--
Warhol's Law: every Usenet user is entitled to his or her very own
fifteen minutes of flame -- The Squoire
|
|
0
|
|
|
|
Reply
|
roberson
|
11/17/2003 6:40:36 PM
|
|
|
1 Replies
576 Views
(page loaded in 0.841 seconds)
Similiar Articles: Pix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ...I have established VPN connection from one Pix 506 to several Pix 501 for server admin purposes. However, I do not want it to be possible to initiate/... PIX 7.2: no crypto map matching problem - comp.dcom.sys.cisco ...Pix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ... PIX 7.2: no crypto map matching problem - comp.dcom.sys.cisco ..... traffic from local to remote ... NAT on both interfaces. PIX - comp.dcom.sys.ciscoPix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ... I have established VPN connection from one Pix 506 to several Pix 501 for server admin purposes. Display real "isakmp key" on PIX 6.3 - comp.dcom.sys.cisco ...... 837 (the one that does have a static)- ! crypto isakmp key ... Real-Time Resolution for IPSec Tunnel Peer is ... Pix to Pix: Initiate VPN on one side only... - comp ... PIX, PPTP and static NAT? - comp.dcom.sys.ciscoPix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ... PIX, PPTP and static NAT? - comp.dcom.sys.cisco... comp.lang.ruby PIX, PPTP and static NAT? - comp ... Pix 506E IPsec site to site VPN Problem - comp.dcom.sys.cisco ...Pix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ..... sys.cisco What causes: IPSEC ... no crypto map matching problem - comp.dcom.sys.cisco ..... from ... Dynamic and peer-to-peer VPN on the same PIX - comp.dcom.sys.cisco ...Pix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ... I have established VPN connection from one Pix 506 to several Pix 501 for ... Active FTP on PIX not functioning - comp.dcom.sys.ciscoPix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ... Active FTP on PIX not functioning - comp.dcom.sys.cisco... ftp to certain sites and they use the ... Cisco Pix 6.3(5) to Checkpoint FW VPN - comp.dcom.sys.cisco ...Pix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ... I have established VPN connection from one Pix 506 to several Pix 501 for server ... remove vpn link PIX 501 - comp.dcom.sys.ciscoPix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ... I have established VPN connection from one Pix 506 to several Pix 501 for server admin purposes ... Pix to Pix: Initiate VPN on one side only... - comp.dcom.sys.cisco ...I have established VPN connection from one Pix 506 to several Pix 501 for server admin purposes. However, I do not want it to be possible to initiate/... PIX to ASA VPN configuration only initiates one-wayKeywords: PIX, to, ASA, VPN, configuration, only, initiates, one ... PIX and an ASA and the tunnel can only be brought up from one side or the ... won't initiate from the PIX ... 7/21/2012 11:17:41 PM
|
|
|
|
|
|
|
|
|