I have a vpn set up in a client server config between two locations on pix devices, mainly because there are remote vpn user's that vpn in to the main pix as well. I've now been instructed to set up a standard lan to lan vpn between the two sites, with the explanation that the main site (server) can't send traffic to the remote site (client). they've tried pings, rdp, http etc. I;ve never heard this before, and would assume bad access lists, though i;ve found a reference to 6.3(4) and prior being classfull, and assuming a 172.x network is always a full class b. that might cause an issue on here, as we are both on a 172 subnet, but both with a 24bit mask. we(client) talk to them(server) on every protocol with no issue. now here;s the catch, i only manage the remote site, the host site is manage by the main company's IT dept, and they;ve contracted us as a local it dept to do all the hands on work needed. so i don;t have access to their pix, all i know is i's a 515 series, i do know however the pix on our pix is running 6.3(1). my first question is, is this indeed true? will a client/server vpn between two pix devices result in a one way vpn? my second is, will the main pix support both being a vpn server, then having a seperately configured lan to lan vpn with another pix device? if the latter is true, then great, i can creat a config in 5 mins for both ends and be done.