tailieunhanh - Using PIX Firewall in SOHO Networks

PIX Firewall version lets you use PIX Firewall as an Easy VPN Remote device when connecting to an Easy VPN Server, such as a Cisco VPN 3000 Concentrator or a PIX Firewall. This functionality, sometimes called a “hardware client,” allows the PIX Firewall to establish a VPN tunnel to the Easy VPN Server. Hosts running on the LAN behind the PIX Firewall can connect through the Easy VPN Server without individually running any VPN client software. | CHAPTER Using PIX Firewall in SOHO Networks This chapter describes features provided by the PIX Firewall that are used in the small office home office SOHO environment. It includes the following sections Using PIX Firewall as an Easy VPN Remote Device Using the PIX Firewall PPPoE Client Using the PIX Firewall DCHP Server Using the PIX Firewall DHCP Client Using PIX Firewall as an Easy VPN Remote Device This section describes the commands and procedures required to configure the PIX Firewall as an Easy VPN Remote device. It includes the following topics Overview Establishing Connectivity Configuration Procedure Overview PIX Firewall version lets you use PIX Firewall as an Easy VPN Remote device when connecting to an Easy VPN Server such as a Cisco VPN 3000 Concentrator or a PIX Firewall. This functionality sometimes called a hardware client allows the PIX Firewall to establish a VPN tunnel to the Easy VPN Server. Hosts running on the LAN behind the PIX Firewall can connect through the Easy VPN Server without individually running any VPN client software. You must select one of the following modes of operation when you enable the PIX Firewall as an Easy VPN Remote device Client mode In this mode VPN connections are initiated by traffic so resources are only used on demand. In client mode the PIX Firewall applies Network Address Translation NAT to all IP addresses of clients connected to the inside higher security interface of the PIX Firewall. To use this mode you must also enable the DHCP server on the inside interface as described in Using the PIX Firewall DCHP Server. Network extension mode In this mode VPN connections are kept open even when not required for transmitting traffic. This option does not apply NAT to any IP addresses of clients on the inside higher security interface of the PIX Firewall. Cisco PIX Firewall and VPN Configuration Guide I 78-13943-01 5-1 Chapter5 Using PIX Firewall in SOHO Networks Using PIX Firewall as an Easy VPN Remote Device In .