How do I recollect my password?
PIX-PIX IPSec VPN
Hello Guest
  
  • Login
• Register…
• Start blog
  • Who, Where, When
• What can I do?
• What to Read?
  • Polls
• Avatars
• Interests
  • Cities and Countries
• Random blog
• Users search
  • Search
• Games
• Tests
• RYXI
  • Сообщества
• Talxy Chat
• Horoscope
• Online
 
Зарегистрируйся!

RYXI > Security > PIX-PIX IPSec VPN 12 May 2005 22:51:51

  Recent blog posts: 
  They have birthday today: 
  Forums:   
  Discuss: 
  Recent forum topics: 
  Recent forum comments:
  Moderators:

PIX-PIX IPSec VPN

John 12 May 2005 22:51:51
 Is there a way to query a PIX to see if it has established a tunnel to
another PIX (without simply sending ICMP's or something over the
connection? I'm working to setup a PIX-PIX vpn, but due to some routing
issues, I won't be able to test for a week or so to verify that the
tunnel has been established.

Thanks.

John
Add comment
Walter Roberson 12 May 2005 22:51:51 permanent link ]
 In article <k%Mge.1569$Lu6.113­6@newssvr19.news.pro­digy.com>,
John <ctcmptrdr@nospam.s­bcglobal.net> wrote:
:Is there a way to query a PIX to see if it has established a tunnel to
:another PIX (without simply sending ICMP's or something over the
:connection?

Cisco PIX specific issues often get the best response in
comp.dcom.sys.cisco­.

:I'm working to setup a PIX-PIX vpn, but due to some routing
:issues, I won't be able to test for a week or so to verify that the
:tunnel has been established.

Up through PIX 6.x, there is no SNMP OID to query the PIX routing tables
or to query the PIX VPN tables or even to query the PIX active
VPN count. That changed in PIX 7.0(1) which is too new to really
trust for production sites.

If you have access to the PIX, via serial console, telnet, or ssh,
then show ipsec sa will show you the active Security Associations.
But PIX tunnels are normally initiated "on demand" so you would
need -some- traffic in order to kick the tunnel. That might be a bit
tricky if you can't attach -something- on the right IP range to one
of the PIXes.

If you want to test out whether the transforms match up and so on,
then what you can do is include in the crypto map match-address ACL
the -public- addresses of the peers. Traffic sourced from the PIX
itself will be included in the tunnel if you name the outside
IPs -- a useful trick if you want the syslogs to go securely. Anyhow,
once those are in there, you could ping from the one pix to the
other PIX and watch to see if the tunnel gets negotiated properly.
--
'ignorandus (Latin): "deserving not to be known"'
-- Journal of Self-Referentialism­
Add comment
 

Add new comment

As:
Login:  Password:  
 
 
  
 
Пожалуйста, относитесь к собеседникам уважительно, не используйте нецензурные слова, не злоупотребляйте заглавными буквами, не публикуйте рекламу и объявления о купле/продаже, а также материалы нарушающие сетевой этикет или УК РФ.


RYXI > Security > PIX-PIX IPSec VPN 12 May 2005 22:51:51

see also:
Re: Storing JPEGs on my 330gig Tivo2
I like the new feature.
пройди тесты:
see also:
Canon Pixma IP1500 how to replace waste…
What to look for in a MP4 player…

  Copyright © 2001—2008 RYXI
Idea: Miсhael Monashev
Помощь и задать вопросы можно в сообществе support.ryxi.com.
Сообщения об ошибках оставляем в сообществе bugs.ryxi.com.
Предложения и комментарии пишем в сообществе suggest.ryxi.com.
Информация для родителей.
Write us at:
If you would like to report an abuse of our service, such as a spam message, please .