cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
475
Views
0
Helpful
6
Replies

ASA and Cisco VPN question

chris.damore
Level 1
Level 1

I am having an issue on a new ASA. I am able to connect to the customer?s network using the Cisco VPN client, but I am not able to PING or access anything on the customers network. What needs to be done to fix this???

There is a route on the customer?s router pointing back to the firewall for the IP range you get when you VPN in?

Thanks,

Chris

2 Accepted Solutions

Accepted Solutions

try adding to ASA...this is disabled by default

isakmp nat-traversal

View solution in original post

Thanks, please rate.

No, it is needed for pix as well. ASA 7.2, the command is "crypto isakmp nat-traversal".

It is necessary if vpn client is connecting behind nat. Allows ipsec to be encapsulated in udp port 4500. The transport tab I mentioned is in the connection entry properties, if you click modify. You will see enable transparent tunneling over udp.

View solution in original post

6 Replies 6

acomiskey
Level 10
Level 10

The config of the ASA would help. Without the config we can only guess, usually this is a nat-t issue. Make sure in vpn client config on the transport tab that you have "Enable transparent tunneling" checked.

I have attached the config for the ASA.

I don't see a transport tab on my VPN client...

Thanks,

Chris

try adding to ASA...this is disabled by default

isakmp nat-traversal

That fixed it! You are the man!!

Is this something new you have to do for the ASA?

Thanks again,

Chris

Thanks, please rate.

No, it is needed for pix as well. ASA 7.2, the command is "crypto isakmp nat-traversal".

It is necessary if vpn client is connecting behind nat. Allows ipsec to be encapsulated in udp port 4500. The transport tab I mentioned is in the connection entry properties, if you click modify. You will see enable transparent tunneling over udp.

I understand now...

Thank you very much for all of your help with this!!!!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: