cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
328
Views
0
Helpful
2
Replies

PIX 7 - Multiple remote VPN sessions from same public IP

Hi,

Here is my problem:

Employee A and employee B make VPN connections to the same PIX with their Cisco VPN clients. Both employees are behind the same NAT device, hence have the same public IP address.

As soon as the second employee initiates the VPN connection, the first employee is disconnected.

I have a similar situation with a PIX version 6.x, and this does not occur. Both employees can connect at the same time, with the same credentials.

Here's the remote access VPN configuration that I use:

group-policy gpolicy attributes

dhcp-network-scope 10.X.X.X

vpn-simultaneous-logins 5

vpn-tunnel-protocol IPSec

ipsec-udp enable

split-tunnel-policy tunnelspecified

split-tunnel-network-list value splitTunnelAcl

user-authentication enable

client-firewall none

username remoteuser password remotepass

username remoteuser attributes

vpn-group-policy labtronix

vpn-simultaneous-logins 2

vpn-tunnel-protocol IPSec

group-lock value vpngroup

tunnel-group vpngroup type ipsec-ra

tunnel-group vpngroup general-attributes

address-pool ip_pool

default-group-policy gpolicy

Any and all input is appreciated.

Thanks.

1 Accepted Solution

Accepted Solutions

acomiskey
Level 10
Level 10

Most likely nat-t problem

add "isakmp nat-traversal" to pix

View solution in original post

2 Replies 2

acomiskey
Level 10
Level 10

Most likely nat-t problem

add "isakmp nat-traversal" to pix

Absolutely right, don't know how I missed that.

Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: