I have ezvpn configured with an acl trigger between a 2811 router and a 877 router, the latter being the client. PC1 is a host behind the 877 and can trigger the VPN tunnel establishment by ping or http, etc, which is seen on both routers. From the 877 router I can ping the Corporate site hosts. But the PC1 cannot establish connection with the hosts, even if it can trigger the VPN connection. Anyway, the IPSec SA encryption and decryption counters are both increasing.
What could be the problem? I have tried both client mode and network extension mode.