pix501 vpn to connect but can not get anywhere

That's how I'm Setup. DSL > linksys wireless router > pix 501. The wireless connects to a cisco 2924 > router 3com > line T1. The T1 line is used for a secure Web site to which we have access. I have the pix configuration, I can connect to the vpn and get an ip address, but I can only ping the external interface of the pix, nothing else. I want to be able to rdp in some machines on the local network, but I can't see them. The CLI I ping the router (10.29.30.238) of 3com, but not all the machines in the local network. (192.168.50.1) inside of the LIS, which connects the outside of her route (192.168.50.2) Linksys, the lan interface of linksys (10.29.30.102), which links outside the pix (10.29.30.103) and the inside of the pix (10.29.31.1), vpn clients receive an ip address of 10.29.31.50.59.

Building configuration...

: Saved

:

6.3 (5) PIX version

interface ethernet0 car

interface ethernet1 100full

ethernet0 nameif outside security0

nameif ethernet1 inside the security100

activate the password xxx

passwd xxx

pixfirewall hostname

domain ciscopix.com

fixup protocol dns-length maximum 512

fixup protocol ftp 21

fixup protocol h323 h225 1720

fixup protocol h323 ras 1718-1719

fixup protocol http 80

fixup protocol pptp 1723

fixup protocol rsh 514

fixup protocol rtsp 554

fixup protocol sip 5060

fixup protocol sip udp 5060

fixup protocol 2000 skinny

fixup protocol smtp 25

fixup protocol sqlnet 1521

fixup protocol tftp 69

names of

access-list 101 permit ip 10.29.31.0 255.255.255.0 any

pager lines 24

opening of session

notifications of recording console

ICMP allow all outside

ICMP allow any inside

Outside 1500 MTU

Within 1500 MTU

external IP 10.29.30.103 255.255.255.0

IP address inside 10.29.31.1 255.255.255.0

alarm action IP verification of information

alarm action attack IP audit

IP pool local Test 10.29.31.50 - 10.29.31.59

location of PDM 10.29.30.0 255.255.255.0 outside

location of PDM 10.29.31.0 255.255.255.0 inside

location of PDM 192.168.5.0 255.255.255.0 outside

location of PDM 10.29.30.0 255.255.255.0 inside

PDM logging 100 information

history of PDM activate

ARP timeout 14400

Global 1 interface (outside)

NAT (inside) 1 0.0.0.0 0.0.0.0 0 0

Access-group 101 in external interface

Route outside 0.0.0.0 0.0.0.0 10.29.30.102 1

Timeout xlate 0:05:00

Timeout conn 01:00 half-closed 0:10:00 udp 0: CPP 02:00 0:10:00 01:00 h225

H323 timeout 0:05:00 mgcp 0: sip from 05:00 0:30:00 sip_media 0:02:00

Sip timeout - disconnect 0:02:00 prompt Protocol sip-0: 03:00

Timeout, uauth 0:05:00 absolute

GANYMEDE + Protocol Ganymede + AAA-server

AAA-server GANYMEDE + 3 max-failed-attempts

AAA-server GANYMEDE + deadtime 10

RADIUS Protocol RADIUS AAA server

AAA-server RADIUS 3 max-failed-attempts

AAA-RADIUS deadtime 10 Server

AAA-server local LOCAL Protocol

Enable http server

http 0.0.0.0 0.0.0.0 outdoors

http 10.29.31.0 255.255.255.0 inside

No snmp server location

No snmp Server contact

SNMP-Server Community public

No trap to activate snmp Server

enable floodguard

Sysopt connection permit-pptp

Telnet 0.0.0.0 0.0.0.0 outdoors

Telnet 10.29.31.0 255.255.255.0 inside

Telnet timeout 5

SSH timeout 5

Console timeout 0

VPDN PPTP-VPDN-group accept dialin pptp

VPDN group PPTP-VPDN-GROUP ppp mschap authentication

VPDN group PPTP-VPDN-GROUP ppp encryption mppe auto

client PPTP-VPDN-GROUP VPDN group configuration address local Test

VPDN group VPDN GROUP-PPTP client dns ISP dns ips configuration

VPDN group VPDN GROUP-PPTP pptp echo 60

VPDN group VPDN GROUP-PPTP client for local authentication

VPDN username user1 password *.

VPDN allow outside

VPDN allow inside

dhcpd address 10.29.31.2 - 10.29.31.33 inside

dhcpd lease 3600

dhcpd ping_timeout 750

dhcpd outside auto_config

Terminal width 80

Cryptochecksum:xxx

: end

[OK]

Yes, if you RDP on a server inside the pix, you can access a server outside the pix (in the 10.29.30.x network).

There are a few requirements for this:

-The server your RDP first needs to have a route by default for the pix (or at least a route to network 10.29.30.x via the pix)

-The server outside the pix must have a route to the Pix. (He needs a route for 10.29.31.x pointing to the external of the pix interface) This can be done with "route add" in a dosprompt

Tags: Cisco Security

Similar Questions

Maybe you are looking for

  • Bookmark restoring crashes Firefox so need to export the previous backup and import to restore

    Attempt to synchronize my home and my work of bookmarks. Started at home, but they are ones I want to overwrite; I want that work to master all. When I realized that I couldn't choose which computer was the dominant set, I stopped and waited until I

  • We all need a scientist emoji

    HI, me and Proffesor Durand, the two have recently agreed that a Professor emoji must be added immediately, thank you and I hope to see the new emoji-

  • Complete BIOS fails to update successful!

    Dear Experts, I have a HP Pavilion Elite e9150t CTO desktop PC (product number: NY810AV) I've recently upgraded from Vista to Windows 7 and have experienced several accidents to blue screen. One of the ideas is to update my Bios. I happy to update my

  • It has Blackberry support Push Notification (aka Google PN) 10

    Dear supporters, We develop game for BB 10, coding only with native code without using a waterfall. We want to apply Push Notification service (aka Google PN). But I can't find any information guide how to do this. I mean PN using native code, not ca

  • JVM 104 Exception on GaugeField progress implementing?

    Hello I use Eclipse for Java in BlackBerry plugin. I am fairly new to BlackBerry App development. I am trying to create a GaugeField that will show how to complete the year, nothing complicated. When I try to build the GaugeField with a variable as t