Re: Pix 520 tunnels

Paul Melson <[email protected]>
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
On Tue, Jun 23, 2009 at 12:08 PM, Halchishak, John<[email protected]> wrote:
> We have two pix (actually three, one failover) 520s that I’m trying to setup
> multiple tunnels. The two office locations have a tunnel up between them
> with 2 peer address on the main end and a single on the other. We have need
> to establish other tunnels at various times to clients. I can’t seem to get
> a second tunnel up without adding it to the existing named tunnel config as
> a third peer and even then it tends to flap our tunnel between the offices.
> Is there some way to accomplish this scenario without causing our tunnel
> problems?

Yes.  I'm betting that the problem is in the way you have the
crypto-map match access-lists configured.  Seeing the config would be
helpful to diagnosing the issue.

You may also have a problem with the actual version of PIX OS you're
running.  Also, at this point, since the 520's are so old that their
replacement model (525) has been end-of-life for 2 years, replacing
them is pretty much imminent.  And since the ASA's have all new VPN
code (based on the VPN3K), mesh and hub & spoke VPN tunnels work a lot
better.

PaulM
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.