Setting up PIX515E VPN for two networks

Hello,
We have a PIX515E and I want to set it up so it can serve client VPN connections for a network on the inside interface and also for a network on the dmz interface.
On a client machine we set up the ip address of the PIX in a VPN connection and the user can log on using credentials and domain. Now the PIX has to look up credentials using RADIUS, but some users are known on domain A (inside interface) and some users are known on domain B (dmz interface). Domain B is completely different and uses other internal ip addresses, dns servers, ip pool etc.
Already I have set up VPN for the inside interface and that was easy and it works ok.
But can I create such a configuration? We only have one DSL line and we want both networks (domain A 192.168.1.x and domain B 192.168.10.x) to go through this PIX.
Your help is more than appreciated!
Regards,
Frank

rob,
i don't know your budget requirements, but here is a relatively easy solution:
http://www.apple.com/server/macosx/features/networkingvpn.html
and here is an OSS solution that will take a bit more work (but should run on an older box with bsd, linux, or os x running on it):
http://openvpn.net/
cheers,
b

Similar Messages

  • How can I set up my Mac for two users to share photos, music etc

    How can I set up my Mac for two users to share photos, music etc?

    On the Mac with the libraries you want to share:
    iTunes Preferences click on the Sharing tab and put a tick in 'Share by library on local network'.
    iPhoto Preferences click on Sharing and put a tick against 'Share my photos'.
    When launching the same apps on other Macs on the network the libraries should be available, listed on the left.

  • HT1424 how do i set up the vpn for the ios

    how do i set up vpn for the ipad2

    Answered here: how do i set up the vpn for the ios

  • Unable to set the ip address for hosted network client after creating WIFI hotspot

    Original Title: INTERNET CONNECTIVITY PROBLEM WITH MY LAPTOP WIFI HOTSPOT
    HI all
    I am able to use internet connection from my lap hotspot, when the internet source is Public or private wifi.
    so I know the cmd window commands for hotspot and settings of client(sharing to hosted network client, assigning IP address etc.,)
    but the problem I am facing is slight different
    I am using my cdma wireless broadband datacard as my source internet connection(Reliance netconnect +)
    when I try to create hotspot for this, as usual I am able to create the hotspot and able to share the internet to hostednework client.
    but I am unable to set the ip address for hosted network client, if I try to set ip 192.169.137.1 and 255.255.255.0
    as soon as I close the window, the ip address also disappears
    when connect my android phone to that hotspot, it is able to connect but there is no internet connectivity.
    when I check the hostednetwork client for packet transmission, both sent and received packet is happening., I mean transmitting
    so what cause the failure in internet connectivity but success in hotspot connectivity?
    check the screen shots...
    can u help me..
    its little complicated

    Hi,
    Please make sure the Ad hoc connection IP adress is at the same range with your local connection. In addition, how about recreate the ad hoc connection for test, please have a try.
    If problem persists, please use Network troubleshooter in Action Center to fix this problem for test.
    Roger Lu
    TechNet Community Support

  • One server for two networks

    Hello,
    I do not already have a Mac Server but I'm planning to buy one, but first of all I got a question.
    Is it possible (if the server has two or more ethernet ports) to divide the services on the different ports ?
    In my example I want to represent my homepage and other web services on the one ethernet port, that is connected to the web and on the other port I want to enable screen sharing, xgrid and so on to support the local network. I now want to know if it is possible to set up different options for every ethernet port.

    Is it possible (if the server has two or more ethernet ports) to divide the services on the different ports ?
    You can have (and use) as many ports as you like. Most of my servers have 4.
    The issue is in controlling the services. By default, each service will typically listen on all interfaces, meaning they're available from all networks.
    To do what you want requires a little tuning of each service to tell it how and where to run. The configuration is based on the service (which ports to run on) rather than the port (which services to support).
    The specifics varies by service. It''s easy, for example, to do this with Apache - just tell it the IP address for each site and you're done. It's relatively easy for most of the file sharing protocols. Off hand, I can't think what's involved in ARD or XGrid.
    Worst case, even if there isn't an easy mechanism for binding a service to one port, there's always the firewall which you can use to block traffic on the ports you don't want. Not a perfect solution, but it does help.

  • How can I set up a VPN between two MacBook Pros

    I am about to buy a new MacBook Pro, I will be leaving my old MacBook Pro in my office in Nicaragua and traveling with my new MBP. I would like to be able to access files on my old laptop from the road, I imagine using some sort of VPN software to patch into my old computer as long as it is on and connected to the Internet.
    Can you help me to set this up. It feels as though it could be difficult, but I imagine it si much simpler than I think.
    Thanks,
    Richard.

    See if this helps
    http://www.macstories.net/tutorials/how-to-set-up-a-vpn-server-on-your-mac-and-a ccess-everything-remotely-with-an-iphone/
    http://forums.macrumors.com/showthread.php?t=1661825

  • Setting up a Server for Small Network

    I have a workgroup of 3 people all on macs running OS X. I have a PowerMac Quad and I want to set it up as a server so that my entire workgroup can access files from it in order to run InDesign and InCopy. How do I do this?
    Thanks in advance!

    OK, so I guess that I had already figured out that this is your first network. Let's have some fun...
    But in your your first post, you stated:
    I have a PowerMac Quad and I want to set it up as a server so that my entire workgroup can access files from it in...
    And no, 'server' won't be a separate user on the Quad. The Quad is the server, right?
    Quad=Computer=server.
    You are configuring the Quad with several new accounts.
    You
    Joe
    MaryLou
    Find this in SystemPreferences>Accounts. Unlock. Click the little Plus sign to add users.
    I would suggest setting the Quad with a static IP address inside your little LAN (local area network). You can find the steps by searching this group for 'static ip', or looking into systempreferences>Network>Built-In...
    You should really read up on some of these network basics (like finding IP address...)
    Don't apologize for your ignorance. Ignorance can be cured, but you'll need more than a hand-holding here in the Discussions.
    I will help, but show us that you're willing to help, too.
    Stop back when you've learned how to:
    a) find your IP address,
    b)set the Quad with a static IP,
    c)search the Discussions

  • CT5508 for two networks

    Hello
    Following customer request/desire I am exploring a "strange" CT5508 config.
    Before diving in to it deeply I would like to know if my idea is possible at all.
    This is what I need to start from:
    1. Network is divided in two pieces , let's say "LEFT" and "RIGHT". The two pieces can only communicate through Firewall.
    2. CT5508 will be installed physically close to two switches, one in each LEFT and RIGHT network.
    3. Access Points will be present in both LEFT and RIGHT network and need to be controlled by single CT5508
    4. We need to keep wifi/capwap traffic in both networks as much as possible separated
    This is my idea:
    1. No LAG
    2. Have CT5508 SFP Distr Ports 1 through 4 connected to switch in LEFT network; ports 5 through 8 connected to switch in RIGHT network
    2. Have AP Manager intf 1 through 4 associated to distr ports 1 through 4
                  IP Addresses of AP manager Intf 1 through 4 from IP Subnet 1 and VLAN LEFT
    3. Have AP Manager intf 5 through 8 associated to distr ports 5 through 8
                  IP Addresses of AP manager 5 through 8 from IP Subnet 2 and VLAN RIGHT
    4. Have different DHCP servers assigned/defined for LEFT and RIGHT network.
    With this setup the question I can not answer from the CT5508 documentation is this one:
    DHCP discover copies from AP in "LEFT" network come in over distr interfaces 1 through 4.
    On which distri ports will CT5508 reply/offer to this DHCP discover from AP?
    I hope this reply to go out over only distr ports 1 through 4 so that the DHCP-based Controller selection in the AP can select among AP manager intfs dedicated to the LEFT network.
    Correct?
    Going one step further: is this approach compatible with e redundant controller setup?
    Thanks a lot for your help and any observation/warning on the subject.
    Regards
    Fred

    Not possible, if you do LAG, all physical ports connect to a single switch (if dual switch, then it has to be VSS pair)
    If customer require this sort of seperation, advise them to buy two WLC
    HTH
    Rasika
    **** Pls rate all useful responses ****

  • Ability to set same Start date for two different discrete Job in ASCP

    We have two ATO Items and these to be built & shipped together which have different leadtimes, How we can have achieve same start date when we release from ASCP.
    E.g: ATO_Model1*24234 SO Line 1, the rolled up LT=10Days
    ATO_Model2*325325, the rolled up LT=3
    So, under normal scenario ASCP will suggest two different release dates based on LT. So, I would like to start both Job togther considering the max leadtime.
    Hoping for your expert advice.
    Thanks
    Edited by: user604737 on Nov 10, 2010 9:55 AM

    Hi,
    964188 wrote:
    It is a date
    Such as
    10/31/2012 11:55:03 PMThen, as Hoek says, you don't want TO_DATE. For example:
    WHERE   TRUNC (start_datetime) = TRUNC (SYSDATE - 7) or the more efficient
    WHERE   start_datetime >= TRUNC (SYSDATE - 7)
    AND     start_datetime <  TRUNC (SYSDATE - 6)Also, it doesn't look like the EXISTS sub-query is corelated to the main query. That's almost certainly a mistake.
    If you're still having trouble, post your revised query, a little sample data (CREATE TABLE and INSERT statements). Point out where that query is givimg the wrong results, and explain how to get te right results.
    See the forum FAQ {message:id=9360002}

  • Setting up document for two-colour printing

    I'm creating a document that will be printed using two colours: black and a Pantone ink. In the Swatches panel I have deleted all the swatches except for Black and my Pantone colour (and obviously None, Paper and Registration are still there). I have also created some mixed-ink swatches based on the black and Pantone colour.
    I notice, however, that the Ink Manager still displays Cyan, Magenta and Yellow as well as the Black and Pantone. Acrobat's Ink Manager does the same, depsite the Preflight showing that it only produces two plates. (In the Output Preview, only the Black and Pantone channels show coverage, but the crop marks show on all five channels.)
    Should I be concerned? Is there a way of setting up a document for two-colour printing that I've missed?
    Any advice would be appreciated.

    The ink manager is not a problem, bu the mixed colors potentially are, depending on the press being used. Some small 2-color presses use a single blanket and mix the ink on the blanket for overprints (which is what mixed inks are), creating a path for cross-contamination of the inks that can muddy the colors all around. You might want to verify that this will not be a problem on your job.

  • Seperate libraries for two ipods on same computer

    how can i set up seperate libraries for two ipods on same computer . running xp . after installing software for second ipod , i only have one version of itunes ,with only one library .tried setting up seperate playlists but that didnt help . thanks for help!

    The only way I know to have two entirely separate iTunes libraries on one computer is to have two Windows or Mac user accounts: How To Use Multiple iPods with One Computer

  • Password for wireless network not remembered

    I am stuck with the following situation. I have a wireless network overhere, which is a 802.1X-type network which consists of a huge number of different base stations connected together, which requires me to login and has TTLS (PAP) type identity control.
    When I configure this into the Internet Connect application, with my password, it connects. However, on reboot, the Finder immediately asks for my password. When I look in Internet Connect, it's still there, but when I look in System Prefs, the password is not there (only a blank field). When I enter it, click OK, and check the dialog again, the password is already gone into the wind.
    I deleted all entries of the network in all my keychains, reinstalled my system and now I've set the keycahin entry for the network accessible by all programs, but that doesn't help me either. I had a Macbook here not long ago, which didn't suffer from this problem (however, it did not reconnect after sleep/reboot all the time, but never asked me for my password).

    Do not check "Remember Networks this computer has joined."
    In Advanced>Preferred Networks, enter the name of your Network. This is how I have mine set up and I have not experienced any more problems like yours, although I did in the past. In Preferred Networks, I have redundantly entered the same name twice, just in case it skips off to the second one. Probably not needed, but it's been working fine like that for a long time.
    However, since I don't have an Airport Extreme, I don't use Airport Utility. Definitely try rebooting the AE. Might try applying or reapplying the 10.6.8 Combo update.

  • I am using an Airport Extreme for wireless and a Netgear VPN Switch for wired connections.  How do I get the two networks to connect?

    I am using an Airport Extreme for wireless and also have a Netgear VPN Switch (FV5318) for internal wired ethernet connections.  How do I get the two networks to connect to each other?

    Tesserax, I would like to keep the Airport Extreme in nplace before the Netgear FVS318 switch because I am using all of the 8 ethernet outputs distributed to 8 differerent locationsl  This way I can just use one of the LAN outputs from the Airport to feed the FVS318.  Here is what I think I am hearing you say:
    Tne reason why the wired and wireless devices are not communicating is because the FVS318G is also a DHCP server and in conflict with the AEBS.
    To remedy the situastion here is probably what I need to do in order:
    1. Change the LAN IP Address of the Netgear FVS318G to be the same subnet of the Airport Extreme.
    2. Then, disable the Netgear FVS318G as a DHCP server.
    3. Make sure the ethernet cable from the LAN port of the Airport Extreme connectis to the LAN port of the Netgear FVS318G.
    4. Restart everything.
    Can you provide me the steps I need to take to get the right IP addresses from the Airport Extreme to put into the Netgear to fix the conflict?  I have the Airport Utility.  I also have two airport express hot spots, and two Apple TVs in addition to computers attached to the 8 ethernet lines.
    Thank you.
    Steve

  • How can I find the all path available for a MPLS VPN in SP network

    How can I find the all path available for a MPLS VPN in SP network between PE to PE and CE to CE?

    Hi There
    If we need to find all the available paths for a remote CE from a local PE it will depend upon whether its a RR or non-RR design. If the MP-iBGP deisgn is non-RR  the below vrf specific command
    sh ip bgp vpnv4 vrf "vrf_name"  will show us the MP-iBGP RT for that particular VPN. It will show us the next hop. Checking the route for same in the Global RT will show us the path(s) available for same ( load-balancing considered) .Then we can do a trace using the Local PE MP-iBGP loopback as source to remote PE's MP-iBGP loopback to get the physical Hops involved.
    However if the design is RR-based there might be complications involved when the RR is in the forwarding path ie we have NHS being set to RR-MP-iBGP loopback and the  trace using the Local PE MP-iBGP loopback as source to remote PE's MP-iBGP loopback will get us the physical Hops involved.
    If we have redundant RRs being used with NHS being set then the output of sh ip bgp vpnv4 vrf "vrf_name" will show us two different available paths for the remote CE destination but just one being used.
    RR-based design with no NHS being used will always to cater to single path for the remote CE detsination.
    So in any case the actual path used for the remote CE connectivity would be a single unless we are using load-balancing.
    Hope this helps you a bit on your requirement
    Thanks & Regards
    Vaibhava Varma

  • Confused how to set-up a PC & laptop with Cisco WRVS4400N VPN for home use

    Just bought a new PC and laptop and was recommended by (CDW) to use a Cisco WRVS4400N to set up the VPN.
    For home use, only the PC and laptop, both running Windows 7.  I use Comcast as my ISP.
    The mountains of docs confuses me to no end, can anyone simplify this for me.  I look at all the details and do not know where to start.
    In short,
    (1) configure router to recognize my PC and Comcast, and I guess the laptop.
    (2) configure laptop to go wireless and communicate with PC.
    Any assistance would be much appreciated.
    Thanks,
    Terry

    For a very small office and a minimum of admin and tech know how, one approach i'd suggest is to not worry about user id collisions at all. any time anyone wants to use a mac you just set them up as a user, using consistent names/passwords.
    Have a "Work" volume on each mac that has "ignore ownership on this volume" ticked. that way UID collisions aren't important.
    You can make a Desktop folder on the Work volume and make a SYMBOLIC LINK from every user's home that replaces their desktop with the desktop folder on the Work volume.
    Make it known that the user's home is for personal stuff ONLY, and the Work volume (inc the desktop) is where work in progress lives.
    At a later date with some confidence in your network and your admin skills you could impose consistent UIDs using an OD master

Maybe you are looking for

  • Org.apache.xml.serialize.XMLSerializer

    Hi, I am using Eclipse for Weblogic 10.3.4 (OEPE1111). I imported a j2ee project. It doesn't include xercesImpl jar. Where should I add them in? On the Java Build Path screen, there are so many options. Thanks!

  • Navigating tabs in Safari

    I would like to say goodbye to Firefox now and start using only Safari. However there's one function that does not seem to work in Safari which I've been using a lot in Firefox. Navigating the tabs with keybord shortcuts Cmd+1/2/3/4/5 and so on to ch

  • Need documentation

    Need documentation for Various programs in ABAP.

  • Can I make links to elements inside a component edge??  as if they are anchors

    I have a menu on dreamweaver with HTML and a component edge, and I want to link to elements (one,two,three,four) inside to component edge it is possible?

  • Epic in AE problems

    Hey guys, Just starting my first red epic project in AE 5.5.  Installed the epic importers From the labs (after effects and media encoder).  I thought it was all working but then I started to get errors Saying the files were unsupported and they'd go