
4-2
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 4 Using PIX Firewall in SOHO Networks
Using PIX Firewall as an Easy VPN Remote Device
Overview
When used with PIX Firewall Versions 6.2 and higher, you can use a PIX Firewall 501 or PIX 506/506E
as an Easy VPN Remote device when connecting to an Easy VPN Server, such as a Cisco VPN 3000
Concentrator or another PIX
Firewall.
Note PIX Firewall 506/506E platforms, when used as Easy VPN remote devices, do not support the use of
logical VLAN interfaces for sending traffic across a VPN tunnel. Only the actual eth0 and eth1 physical
interfaces on the PIX Firewall 506/506E are supported when used as an Easy VPN remote device.
Figure 4-1 illustrates how Easy VPN Remote devices can be used in a Virtual Private Network (VPN).
Figure 4-1 Using the PIX Firewall as an Easy VPN Remote Device
Internet
83963
PIX Firewall 501
or 506/506E
(Easy VPN
Remote device)
Easy VPN Server
(PIX Firewall,
Cisco VPN 30xx,
or Cisco IOS 12.2(8)T)
ISP router
Push remote
configuration
Remote LAN Central LAN
Easy VPN Remote device functionality, sometimes called a “hardware client,” allows the PIX Firewall
to establish a VPN tunnel to the Easy VPN Server. Hosts running on the LAN behind the PIX
Firewall
can connect through the Easy VPN Server without individually running any VPN client software.
PIX Firewall Version 6.3 or higher used as an Easy VPN Remote device can make use of load balancing
and redundancy features among two or more Easy VPN Servers. To implement redundancy, a list of
backup servers is configured on an Easy VPN Server and is downloaded to your Easy VPN Remote
device. The Easy VPN Remote device automatically redirects its connection request to the next backup
server on its list if it does not receive a response after five seconds.
Load balancing requires the use of Cisco 3000 Series VPN Concentrators for the Easy VPN Servers.
With load balancing, you configure a virtual IP address for the destination of your Easy VPN Remote
device connection. Easy VPN Servers that share a virtual IP address form a load balancing cluster, with
one of the members acting as the master server. The master server receives request, calculates the
optimal server, and directs the connection request to that server.
Two different modes of operation are supported when using the PIX Firewall as an Easy VPN Remote
device:
• Client mode
• Network extension mode
Note If Cisco IP Phones are connected over the VPN tunnel and Session Initiation Protocol (SIP) proxy is used
on the network protected by the Easy VPN Server, you must use network extension mode.
Comentarios a estos manuales