0 pts.
Q:
setting up pix as vpn server in public address environment
In our network all of our addresses are public per the policy of our ISP, (the state of washington). In order to use a pix for the inner firewall I had to incorporate a cisco hack to exclude all addresses from NATing. This was done with a standard access list following cisco instructions.
Now I want to deploy VPNs on the pix using a microsoft radius server and microsoft certificates with cisco easy VPN clients. I haven't found instructions for this combination yet.
When I ran the cisco wizard to configure the pix as a VPN server it errored out. The dump shows the wizard tried to add an extended ACE to the standard ACL I created to avoid NATing and this was refused. Can I change the standard ACL recommended by cisco to an extended ACL without breaking the NAT exclusion function? Also, I'm not sure how to set up the client and pix to use certificates. I don't know what certificates to use and couldn't find information from cisco.
I would appreciate any information to help deploy these VPNs.
Thanks.
rt
ASKED: Apr 5 2005  12:20 AM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0 pts.
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • Bookmark and Share
The ACL hack worked. We were able to do VPNs with shared secrets but haven't figured out the certificate part. Since this must be deployed tomorrow I am reluctantly going with shared secrets.
Unless I find an answer before my job ends here I expect the college will just stay with the shared secret solution.
rt
Last Answered: Apr 6 2005  12:23 AM GMT by astronomer   0 pts.
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

Dane Sauve   0 pts.  |   Feb 4 2010  4:24PM GMT

Generally I do not post on blogs, but I would like to say that this post really forced me to do so! really nice post.