Cannot access some sites behind the pix515e

I started my CISCO PIX 515e in July 2004 with a minimum configuration. The only change I made was to introduce the syslog and 3COM tftp server. Two weeks after my Internet (browsers) users (inside) began to have problems of access to certain sites for example google.com, cnn.com etc when I bypass the firewall, they can access all the sites. When I place them behind the firewall again they cannot access the same places. It seems to me that the firewall is the cause. This could be the cause?

Without seeing your config, it is hard to say, but a proposal, I'd say you're probably out of translation addresses. The PIX must create a translation for the traffic as it comes out, and she does that based on nat/global orders, you have in there. Let's say you have the following:

Global 1 200.1.1.1 - 200.1.1.254 (outside)

NAT (inside) 1 0.0.0.0 0.0.0.0

Then, this indicates the PIX to translate any internal address to 200.1.1.x he died. If all of these 254 global addresses be used however the next person who tries to go out will be denied. If you look at your syslog server, you will see a message like "Unable to create translation."

If you change it above to:

Global 1 200.1.1.1 - 200.1.1.253 (outside)

Global 1 200.1.1.254 (outside)

NAT (inside) 1 0.0.0.0 0.0.0.0

then the first 253 users that come out will have their packages would NAT, then all of the other packages will be PAT had to the 200.1.1.254 address, giving you an extra 65, 000 - odd outbound connections.

If that's not enough (remember that only the user going to a few web sites can open connections to 20-30), then you can change the above to the following:

Global 1 200.1.1.1 - 200.1.1.252 (outside)

Global 1 200.1.1.253 (outside)

Global 1 200.1.1.254 (outside)

NAT (inside) 1 0.0.0.0 0.0.0.0

giving you a 65, 000 - odd additional translations and so on.

Other than that, we would need to see your Setup and your messages to syslog (in the debug level) when these users can't get out.

Tags: Cisco Security

Similar Questions

  • Cannot access some sites

    Hello

    It has been 72 hours since the problem started. I can't access many websites like facebook, twitter, even google and tried a different browsers but still the same. I called my ISP and they said that my there is no problem as long as I'm able to access to many other sites.

    Thank you.

    OK, the symptoms resemble the malware crashed your hosts file (in order to redirect you to malicious Web site when you type in google.com, twitter.com , or other common names) - Please try the fixit from microsoft of http://support.microsoft.com/kb/972034 in order to tackle the problem.

  • "due to an unidentified problem, windows cannot display windows firewall settings" fixed but still can not visit some sites and the laptop now turns off the coast on me. What should I do?

    I have an Apire one laptop with Windows xp service pace 3. I had to restore it to factory about 3 years ago. Some time after that the sound system began to slow and the Synaptics mouse stop working properly. I can move the pointer, but the left click does not work. It works in safe mode but not in normal windows. I used the Acer eRecovery for correct, but it did not work. I tried to download the driver for the mouse on the internet, but some how it could stop the download. I gave up at tring to fix. Some time in late March or early April, I couldn't access internet and after 22:30. I ran the diagnosis that is provided by internet explore and he said that the HTTP and HTTPS worked but the FTP did not work. AVG later told me my firewall is disabled and there was the possibility to reactivate it and I did. After internet explore stop allowing you to enter certain sites that I wanted to enter, I ran the Diagnostics again and he told me that a firewall client has been the cause of the problem. I tried to control my firewall setting, but had that "due to a problem not identified, windows cannot display the firewall settings". I thought AVG was the problem, so I have unintalled then he returned and attempted to access the firewall but got the same message. I typed in Google MySapce and found this site. I followed a few directions given to others in the thread started by joecarpenter33 and discovered that my firewall has been deleted and Base filtering engine has been deleted also. I downloaded and ran Malwarebytes ANti-Malware and SUPERAntiSpyware Free Edition and tdsskiller. MBAM has found a Trojan. The results of the analysis is less to:

    Malwarebytes Anti-Malware (Trial) 1.75.0.1300
    www.Malwarebytes.org

    Database version: v2013.04.10.14

    Windows XP Service Pack 3 x 86 NTFS (secure/setting network Mode)
    Internet Explorer 8.0.6001.18702
    Ziadie Berry: BERRY-LAPTOP [Director]

    Protection: disabled

    10/04/2013-17:44:54
    MBAM-log-2013-04-10 (17-44-54) .txt

    Scan type: quick scan
    Analyze the options enabled: memory | Startup | Registry | File system | Heuristic or Extra | Heuristics/Shuriken | PUPPY | PUM
    Analyze the options disabled: P2P
    Objects scanned: 271656
    Time elapsed: 43 minute (s), 42 second (s)

    The process of memory detected: 0
    (No malicious items detected)

    Modules of memory detected: 0
    (No malicious items detected)

    The registry keys detected: 0
    (No malicious items detected)

    The registry values detected: 0
    (No malicious items detected)

    Registry data items detected: 0
    (No malicious items detected)

    Files detected: 0
    (No malicious items detected)

    Files detected: 1
    C:\RECYCLER\S-1-5-21-4674304-3331980883-3375822000-500\$7832f44fdd2ba165f6ea01bec7f363fd\n (Trojan.0Access)-> quarantined and deleted successfully.

    (end)

    Malwarebytes Anti-Malware (Trial) 1.75.0.1300
    www.Malwarebytes.org

    Database version: v2013.04.10.14

    Windows XP Service Pack 3 x 86 NTFS
    Internet Explorer 8.0.6001.18702
    Ziadie Berry: BERRY-LAPTOP [Director]

    Protection: enabled

    10/04/2013 23:43:49
    MBAM-log-2013-04-10 (23-43-49) .txt

    Scan type: quick scan
    Analyze the options enabled: memory | Startup | Registry | File system | Heuristic or Extra | Heuristics/Shuriken | PUPPY | PUM
    Analyze the options disabled: P2P
    Objects scanned: 269636
    Elapsed time: 49 minute (s), 41 second (s)

    The process of memory detected: 0
    (No malicious items detected)

    Modules of memory detected: 0
    (No malicious items detected)

    The registry keys detected: 0
    (No malicious items detected)

    The registry values detected: 0
    (No malicious items detected)

    Registry data items detected: 0
    (No malicious items detected)

    Files detected: 0
    (No malicious items detected)

    Files detected: 1
    C:\WINDOWS\assembly\GAC\Desktop.ini (Rootkit.0access)-> quarantined and deleted successfully.

    (end)

    I ran the Diagnostics today after Internet explore and my other browsers stop allowing me to internet access. That's what came back:

    Diagnosis of last run time: 17/04/13 17:48:14 WinSock Diagnostic
    WinSock status

    attmpting error information to validate the Winsock base providers: 2
    error not all entries could be found in the basic services provider winsock catalog. A reboot is required.
    user redirection of information in support of the appeal

    Diagnosis of network adapter
    Network location detection

    Info to help home Internet connection
    Identification of network adapter

    Info network connection: name = Local, peripheral network connection = Realtek RTL8102E Family PCI - E Fast Ethernet NIC, MediaType = LAN, type = LAN
    Info network connection: name = wireless, peripheral network connection = Atheros AR5007EG Wireless Network Adapter, MediaType = LAN, type = Wireless
    Info both Ethernet connections and wireless available, ask the user for selection
    required user input action: select network connection
    Info Wireless connection selected
    State of the network adapter

    Info network connection status: connected

    HTTP, HTTPS, FTP Diagnostic
    HTTP, HTTPS, FTP connectivity

    WARN HTTPS: error 12029 connecting to www.microsoft.com: a connection with the server could not be established
    warn HTTP: error 12029 connecting to www.microsoft.com: a connection with the server could not be established
    warn HTTP: error 12029 connecting to www.hotmail.com: a connection with the server could not be established
    WARN HTTPS: error 12029 connecting to www.passport.net: a connection with the server could not be established
    WARN FTP (passive): error 12029 connecting to FTP.Microsoft.com: a connection with the server could not be established
    WARN FTP (active): error 12029 connecting to FTP.Microsoft.com: a connection with the server could not be established
    error could not make an HTTP connection.
    error could not make an HTTPS connection.
    error could not make an FTP connection.
     
    Still, he remains connected to the wirelesss connection, but won't let me access the internet. Right now I use a proxy to help, but access to the sites are limited.

    I used the tweaking software and my firewall is back but, I have yet to visit some sites and the laptop now turns off by itself.

    Hello

    Follow these methods.

    Method 1.

    Start the computer in safe mode with network and run a full scan of computer viruses.

    To start the computer in safe mode: http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx?mfr=true

    Run a full scan of the computer with the Microsoft Safety Scanner to make sure that the computer is virus-free.

    Microsoft safety scanner: http://www.microsoft.com/security/scanner/en-us/default.aspx

    Warning of Security Scanner: there could be a loss of data while performing an analysis using the Microsoft safety scanner to eliminate viruses as appropriate.

    Method 2.

    If the steps above do not help, then try to scan the computer using Windows defender in offline mode and check if that helps.

    Search for spyware and other potentially unwanted software: http://windows.microsoft.com/en-US/windows7/Scan-for-spyware-and-other-potentially-unwanted-software

    What is Windows Defender Offline? : http://windows.microsoft.com/en-US/windows/what-is-windows-defender-offline

    Warning of Security Scanner: there could be a loss of data while performing an analysis using the Microsoft safety scanner to eliminate viruses as appropriate.

    Method 3.

    You can create a new user account and check. Once the new user account works fine, then copy the data from the old user account for the user account.

    How to copy data from a user profile damaged to a new profile in Windows XP: http://support.microsoft.com/kb/811151

    Let us know if you need assistance with any windows problem. We will be happy to help you.

  • Cannot access Pathname you have the appropriate permissions. Cannot download updates gives error code 643 and error code 5. Always gives access denied.

    Cannot access Pathname you have the appropriate permissions. Cannot download updates gives error code 643 and error code 5. Always gives access denied. You do not have the appropriate permissions. I am the administrator. Change all the complete control. Any other suggestions? Possible virus?

    Hello

    You are unable to download the updates?

    Try the following steps to resolve the problem:

    Method 1: Temporarily disable any security (including firewalls) software and check if the problem persists.

    Check out these links:
    http://Windows.Microsoft.com/en-us/Windows7/turn-Windows-Firewall-on-or-off

    http://Windows.Microsoft.com/en-us/Windows7/disable-antivirus-software

    If disabling the security software solves the problem, then contact the manufacturer of the specific security software to fix the problem.

    Important: Antivirus software can help protect your computer against viruses and other security threats. In most cases, you should not disable
    your antivirus software. If you do not disable temporarily to install other software, you must reactivate as soon as you are finished. If you are
    connected to the Internet or a network during the time that your antivirus software is disabled, your computer is vulnerable to attacks.

    Method 2:
    See the article mentioned below and run the Fixit diagnostic tool to fix the error 643.

    You receive error code 80070643 0 x or 0 x 643, code error when you use the Windows Update or Microsoft Update Web sites to install updates:
    http://support.Microsoft.com/kb/958052


    Kind regards
    Afzal Taher-Microsoft Support.
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • I am unable to use the "email us" on some sites Web, the error message is ' no e-mail program associated to this.

    Original title - Outlook Live

    Or direct or Outlook appear on win 7 list of default programs, so I am unable to use the "email us" on some sites Web, the error message is ' no e-mail program associated to this "" go to default programs and associate.   Even though I have a Live (and Outlook account, they are not listed by default in the programs.  I can send and receive emails in 'Live' and prospects, but cannot associate, because they are not displayed.  I don't have MS Office.  I use the email from Comcast, but also does not appear.   Absence of a response, does anyone know how to make the "no e-mail program associated to this" work?

    Hi Michael,

    Please answer this question to get more clarity on this issue.

    • You have installed Windows Live Mail email client?

    This problem may occur if Windows Live Mail or Microsoft Outlook is not installed on the computer.

    If you don't have Windows Live Mail, you can download and install Windows Live Essentials to check the status.

    You can download Windows Live Essentials here: http://www.microsoft.com/en-us/download/details.aspx?id=3945

    Reference article.

    Windows Essentials: http://windows.microsoft.com/en-us/windows-live/windows-essentials-help#v1h=tab4

    Response with the State of the question and we will be happy to offer you our help.

  • Cannot access Windows Gadgets because the message only the administrator is permitted.

    Original title:

    I am logged on as administrator (only 1 person on this computer) but I get messages that only an administrator can access some files (for example the Windows Gadgets))

    I have Windows 7 Ultimate, only one person has this computer (me), I installed as admin (no other account on this computer).  Cannot access Windows Gadgets because the message only the administrator is permitted.  I AM THE ADMINISTRATOR!  Why is this happening?

    Hello

    1. you only receive the error message when you try to access the "Windows Gadgets"? What is the full error received?

    2 have you made any changes to the computer before the show?

    Method 1:

    Step 1:

    Check if you are able to access to the files and programs into account administrator in safe mode.

    Start your computer in safe mode

    http://Windows.Microsoft.com/en-us/Windows7/start-your-computer-in-safe-mode

    Restart the computer to return to normal mode

    Step 2:

    If you are able to access all files and programs to the account administrator in safe mode then I suggest that you create a new user to the administrator.

    Create a user account

    http://Windows.Microsoft.com/en-us/Windows7/create-a-user-account

    Method 2: Try the steps from the following link and check:

    How to open a file if I get an access denied message?

    http://Windows.Microsoft.com/en-us/Windows7/how-do-I-open-a-file-if-I-get-an-access-denied-message

     

  • Googlebot cannot access your site. Has anyone encountered this problem before?

    Hello

    I'm a rookie at this. I just wanted to create a simple site and could use the tools webmasters google crawl my site

    but it happens

    "I received an e-mail from saying: webmaster tools".

    Googlebot cannot access your site.

    Recommended action

    If the site's error rate is 100%:

    • Using a web browser, try to accesshttp://www.graphicsigns.co.nz/robots.txt. If you are able to access it from your browser, your site can be configured to deny access by googlebot. Check your firewall configuration and the site to ensure that you are not denying access by googlebot.
    • If your robots.txt file is a static page, check that your web service has appropriate permissions to access the file.
    • If your robots.txt file is generated dynamically, verify that scripts that generate the robots.txt file are properly configured and have to run. Check the logs of your Web site to see if your scripts fail and if so try to diagnose the cause of the failure.

    If the site's error rate is less than 100%:

    • Using webmaster tools, find a day with a high error rate and review logs of your web server to this day here. Look for errors to access robots.txt file in the logs for that day and fix the causes of these errors.
    • The more likely explanation is that your site is too large. Contact your hosting provider and discuss to reconfigure your web server or by adding more resources to your Web site.
    • If your site redirects to a different host name, another possible explanation is that a URL on your site redirects to a hostname portion of his robots.txt file exposes one or more of these questions.

    Please need your help & expertise to solve this.

    Musch appreciated.

    Hello

    Sitemap.XML is automatically created and updated in Muse. If you are hosting the Business Catalyst, then the sitemap.xml is not created by Muse. It is created by a process that runs periodically on the servers of BC, so it can take up to a day before the sitemap.xml in British Colombia has been updated.

  • AnyConnect client cannot access external sites

    I am installing AnyConnect VPN with no split tunneling. ASA 5505 v8.2. It seems that it should be really easy. I must be missing something.

    I can get AnyConnect users to connect very well and they can access internal sites and on other sites in IPSec tunnel. But no access to internet.

    Internal 10.1.1.x pool VPN is 10.1.1.251 - 253 (list of Temp for the test). I have published the following plotter:

    packet-tracer input outside tcp 10.1.1.253 12345 69.147.125.65 80 detailed

    The last reported point (where it fails) is:

    Phase: 7

    Type: WEBVPN-SVC

    Subtype: in

    Result: DROP

    Config:

    Additional Information:

    Forward Flow based lookup yields rule:

    in  id=0xda7e9808, priority=70, domain=svc-ib-tunnel-flow, deny=false

    hits=364, user_data=0xcb000, cs_id=0x0, reverse, flags=0x0, protocol=0

    src ip=TempVPNPool3, mask=255.255.255.255, port=0

    dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0

    Which means by SVC-WEBVPN?

    A relevant config:

    No ACLs, filters or limitations of policy group on HQ customers.

    Security-same permit intra-interface

    Global 1 interface (outside)

    On advice, I've added: nat (outside) 1 10.1.1.0 255.255.255.0, then I can get no tunnel guests outside guests, but then no IPSec.

    Kind of a weird, that with this, the tracer of package does not change. Continue to deny shows, but the site is accessible.

    When you say tunnel IPsec sites... is that the tunnels IPsec Site to Site on the SAA?

    The command:

    NAT (outside) 1 10.1.1.0 255.255.255.0

    It should allow the AnyConnect customer pool for PATed to Internet.

    If you need clients AnyConnect to access the Internet and the access to remote IPsec tunnels as well, you can do it with policy NAT:

    access-list anyconnect deny ip 10.1.1.0 255.255.255.0 x.x.x.x

    access-list anyconnect deny ip 10.1.1.0 255.255.255.0 y.y.y.y

    access-list allowed anyconnect ip 10.1.1.0 255.255.255.0 any

    NAT (outside) 1 access list anyconnect

    Global 1 interface (outside)

    With the above configuration, you are bypassing NAT for AnyConnect customers when they want to access remote sites through the IPsec tunnels (assuming that x.x.x.x and y.y.y.y for remote networks through these tunnels).

    And the rest of the AnyConnect (10.1.1.0/24) pool will be PATed to Internet.

    Federico.

  • Cannot access bios after installing the video card

    I have a PC HP 800 G1 tour.  When I install an EVA GT 520 external video card I can access is no longer the first screen to get the bios unless I get out the video card.  I want to change the bios to use only the external card, or at least to see the initial splash screen, but cannot access it.  It is running windows 8.1.  I updated the bios to the lasest version and still the same.

    Hello:

    You may need to change some BIOS settings - even if you add an external video card...

    http://support.HP.com/us-en/document/c03653200

  • Cannot access Internet even if the router USB adapter Wireless G made the connection and

    Hello, I recently bought a Wireless-G USB Network Adapter with SpeedBooster model WUSB54GSC to go with my Wireless-G Broadband Router model WRT54G2 and I can't access the internet.  The laptop tells me I am connected and that force is Excellent, but when I open my browser, I can't access any site at all. When I try to add the laptop to my network magic on my computer, it tells me that it cannot connect with the laptop.  My Nintendo Wii and Itouch work perfectly with the router so I think it's my browser settings, but I can't understand it.  Thank you!

    Hey, thanks for trying to help out.  It turns out that my firewall did not allow the laptop to access the internet.  I made a few adjustments on my firewall settings and it all worked out great.

  • WRT110, Vista, wired desktop cannot access utility based on the router's web

    Computer Vista hard wired to the WRT110 cannot access the router. But it CAN get to internet and CAN ping router without losses. The XP machine is wireless, can get internet and CAN ping router without losses, but also can NOT access the router page. Ipconfig displays 192.168.1.1 is the correct default gateway address.  Yesterday, I had to reset the modem to access the router and had to enter all the parameters.  Could access router yesterday but can't today. The IP address is valid from yesterday to tomorrow. I don't understand what has happened to prevent access to the router. I even unplugged the modem to the router and still cannot access router today.  I can't find this problem in the forum, hope this isn't a duplicate request. Thanks for any help

    I have NO idea why, but I can access the Web with IE8 installed utility pages.  Has absolutely no sense to me.  Of course, it must be some kind of safety but my IE use medium-high settings, so I can't imagine what passage of IE7 to IE8 did indeed these parameters.

    Happy now that I can access these pages, finally.  Hope this helps someone else.

  • Cannot access my router through the Explorer configuration page

    I need to do a port forwarding on my router. My internet connection works (even if she falls occasionally) and I can also connect to other computers on my network. However, I cannot access my router through IE page (I get a message saying: page not found). When I go see the map in the options Vista network, the router is not displayed and when I clikc on "See the whole map", I get a message saying that Windows cannot detect any computer or devices.

    My connection to the router is connected, and it is a WRT54G Lyinksys. Any ideas how I can see my router or go to its page layout? Another thing, I went to CMD and the ping command returns a default gateway 192.168.1.1, which is what I have my using the address of the webb page.

    Thanks for any help.

    Hi JBHPUser,

    (a) other router configuration page, you are able to access other Web sites?
     
    (b) what operating system and Internet Explorer version do you use?
     
    This article can be very useful.
     
    You receive an error message in Internet Explorer: "Internet Explorer cannot display the webpage".
    http://support.Microsoft.com/kb/956196
     
    You can also access these links, which is primarily for Windows Vista, but are also applies to Windows 7
     
     
     
     

    Aziz Nadeem - Microsoft Support
  • Win 7 64 bit: cannot access Web sites randomly

    I had this problem for a long time, with several computers and various installations of windows.

    After my computer has been for a few days, I'll suddenly find me unable to access all the web pages. Programs like MIRC, Skype and steam work perfectly, like online games. I just get a generic "unable to connect to the server" error when you try to access Web sites and I cannot ping all websites such as google.com (it instantly timeouts).

    Do ipconfig/release, / flushdns and / renew fixes it for a few minutes before I lose the ability to access the Web sites again.

    Disabling/renewal of the NIC does nothing and troubleshooting of windows doesn't find anything wrong.

    The only semi-permanent solution I found is to restart my computer, but the problem will occur again in a few days.

    Servers using openDNS makes no difference. Nor is switching between ethernet cable and wireless. This problem is not dependent on the browser. Reboot the router it corrects only for a few minutes until I became unable to use websites to access again.

    Does anyone know what the cause of the problem and how to fix it permanently?

    Hello.

    I suggest you to configure the TCP/IP settings and check if it works:

    http://support.Microsoft.com/kb/2779064/en-us

    If the problem persists, I suggest you consult the website of the manufacturer of the laptop computer to download and install the latest network driver and check the results.

    Please let us know if the problem still persists.

  • Cannot access some websites with any browser

    I can't access some websites with any browser

    What happened with a few sites, but who is really upsetting me is https://simply. freetax.com

    I tried IE, Mozilla and Opera

    In each one I click on the link then it takes forever for what it is loading and when it does it is one of the many messages of error according to the site.

    It is not my ISP or router is blocking the site because I can access it from any of the other 4 computers in this House. It seems that the problem is limited to my desktop unit. I tried to disable my firewall and antivirus. I erased from history. I have no idea where to go next.

    Help, please

    Thank you

    Hello

    Thanks for posting your query in Microsoft Community.

    This problem may occur if there is a change in the configuration and network settings.

    See methods below to solve the problem.

    Method 1

    Try running the Fix - It from the link below. He will try to correct the most common problems with the network.

    https://support.Microsoft.com/en-us/KB/299357?WA=wsignin1.0

    If the problem persists, check the method below.

    Method 2

    Try resetting your Internet Explorer and see the link below. He starts the internet explore to the default state.

    http://Windows.Microsoft.com/en-us/Windows7/reset-Internet-Explorer-settings

    NOTE: The Reset Internet Explorer Settings feature might reset security settings or privacy settings that you have added to the list of Trusted Sites. Reset the Internet Explorer settings can also reset parental control settings. We recommend that you note these sites before you use the reset Internet Explorer settings. Also re - activate the Add-ons.

    Check if it helps.

    Method 3

    Web connection issues are frequently a corrupt DNS cache. Flushing the cache is an easy solution to many of these problems.

    Here's how to fix this corrupt DNS cache.

    1 click Start.

    2. type cmd in the search bar.

    3. right click on cmd and select run as administrator.

    4. in the command window, type the following, and then press ENTER:

    ipconfig/flushdns

    5. you will see the following confirmation:

    Windows IP Configuration properly empty the Cache of DNS resolution

    For any Windows help in the future, feel free to contact us and we will be happy to help you.

  • VPN clients cannot access remote sites - PIX, routing problem?

    I have a problem with routing to remote from our company websites when users connect via their VPN client remotely (i.e. for home workers)

    Our headquarters contains a PIX 515E firewall. A number of remote sites to connect (via ADSL) to head office using IPSEC tunnels, ending the PIX.

    Behind the PIX is a router 7206 with connections to the seat of LANs and connections to a number of ISDN connected remote sites. The default route on 7206 points to the PIX from traffic firewall which sits to ADSL connected remote sites through the PIX. Internal traffic for LAN and ISDN connected sites is done via the 7206.

    Very good and works very well.

    When a user connects remotely using their VPN client (connection is interrupted on the PIX) so that they get an IP address from the pool configured on the PIX and they can access resources located on local networks to the office with no problems.

    However, the problem arises when a remote user wants access to a server located in one of the remote sites ADSL connected - it is impossible to access all these sites.

    On the remote site routers, I configured the access lists to allow access from the pool of IP addresses used by the PIX. But it made no difference. I think that the problem may be the routes configured on the PIX itself, but I don't know what is necessary to solve this problem.

    Does anyone have suggestions on what needs to be done to allow access to remote sites for users connected remotely via VPN?

    (Note: I suggested a workaround, users can use a server on LAN headquarters as a "jump point" to connect to remote servers from there)

    with pix v6, no traffic is allowed to redirect to the same interface.

    for example, a remote user initiates an rdp session for one of the barns adsl. PIX decrypts the packet coming from the external interface and looks at the destination. because the destination is one of adsl sites, pix will have to return traffic to the external interface. Unfortunately, pix v6.x has a limitation that would force the pix to drop the packet.

    with the v7, this restriction has been removed with the "same-security-traffic control intra-interface permits".

    http://www.Cisco.com/en/us/partner/products/HW/vpndevc/ps2030/products_configuration_example09186a008046f307.shtml

Maybe you are looking for