access to DMZ (PIX 6.3) from outside through vpn tunnel

  1. Hello !

    PIX 6.3

    I have several branch offices connected to headquarter through vpn
    tunnel (PIX to PIX vpn).
    In headquarter i have DMZ (dmz interface - PIX 515).
    Is it possible to create vpn connection from branch offices to DMZ ?
    I have to put corporate Exchange server there. Exchange should not be
    visible from internet but for some reason it may not be in inside lan.
    Any examples ?

    marcin.kmetko, Feb 20, 2007
  2. Do You wan't to terminate a VPN tunnel somewhere in the DMZ or just
    allow traffic from/to the DMZ to enter the tunnel?
    It's just the same as with any other VPN tunnel. You only have to make
    proper ACLs.
    =?ISO-8859-2?Q?Micha=B3_Iwaszko?=, Feb 21, 2007
  3. Only allow trafic. VPN is terminated in outside interface.
    It should be easy ... but i can't manage it.

    Topology looks like this :

    vpn_client (
    pix (dmz) ---

    vpn_client have access to lan (inside), but i can't get to servers in

    Config :
    nat (inside) 0 access-list 10
    nat (inside) 1 0 0
    nat (dmz) 0 access-list nonat_dmz

    access-list 10 permit ip
    access-list nonat_dmz permit ip

    access-list in_outside permit ip
    access-list in_outside permit ip
    access-list in_inside permit ip
    access-list in_dmz permit ip host any

    ip local pool vpnclients
    vpngroup remote_access address-pool vpnclients
    vpngroup remote_access split-tunnel 10
    vpngroup remote_access idle-time 1800
    vpngroup remote_access password ********

    any idea ?

    marcin.kmetko, Mar 1, 2007
