Full tunneling

Unanswered Question
Feb 22nd, 2007

Hello,

I'm trying to configure remote access using Cisco VPN client (ver 4.6) to my corporate LAN using PIX 515E (ver 6.3.4) like VPN gateway. The thing is that access to corporate servers is doing ok, but I'm not able to go through company's proxy to the Internet. (Split-tunneling is not an option, but just for info, split-tunneling when is added is working too).

Considering information found on Internet that PIX OS 6.x could make some problems to accept remote connections and to handle Internet traffic through one interface, I've tried with an alternate DSL Internet connection and alternate PIX (501/ver 6.3.4) and same configuration (very similar to configuration examples on Cisco's site). But the problem remains, can go to the servers and everything else in my LAN but can't go through proxy.

(ACLs and NAT are allowing anyone to access proxy on port 8080)

Can anyone give me some advice what to do ?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Kamal Malhotra Thu, 02/22/2007 - 07:20

Hi,

Please make sure that proxy server is correctly configured in your browser, meaning the private IP of the proxy server needs to be configured. If it is fine then you might want to capture the traffic behind the PIX.

HTH,

Regards,

Kamal

promonte22 Fri, 02/23/2007 - 03:02

Hi Kamal,

thank you for the quick response.

I've changed proxy IP settings in my browser, but there is no change.

There is something else: I 've done several tests and problem with proxy occurs only when I'm connected via dial-up connection (I tried several phone lines), but NOT via broad connection (ADSL for example) or when directly connected to outside interface of PIX.

So if this can be arranged, that's fine, but if not I'm not disatisfied because dial-up is pretty rare today and still got remote access to servers.

Regards,

Kamal Malhotra Fri, 02/23/2007 - 03:31

Hi,

Its fine if you are okay with the broadband connection. But if you want to try then may be you could goto the setMTU option and lower the MTU for the adapter the Dialup adapter. Please be informed that you will be required to reboot the machine. Then you can try it.

HTH,

Regards,

Kamal

promonte22 Mon, 02/26/2007 - 03:35

Hi Kamal,

MTU default setting fot Dialup adapter is 1300 bytes. What do you suggest for new MTU value ?

Regards,

Aleksandar

Actions

This Discussion