Hello all, I'm currently researching if the following is possible: I have a PIX firewall behind a router performing NAT. The config is basic and resembles the following: Internet --> Router --> PIX -- > LAN I'd like to run VPN (PPTP or IPSEC) on the PIX. I'd like to know if this is possible and if anyone has this implemented. Obviously, the Internet side of the router is public. The PIX side of the router has a private range, and the router is configured with a static translation to the PIX - this would be used as the endpoint for clients. I'm not opposed to running VPN on the routers - just curious if this setup would work with the PIX running VPN behind the NAT router. Thanks for any help, Jason
yes. yuo will just make sure you pass/redirect the correct ports thru to the pix - the ports for esp and isakmp. ( dont recall them offhand. )