PIX 506E VPN caan connect, but no LAN

Answered Question
Apr 17th, 2008
User Badges:

Heelo, We have a 506E with 6.3(3). we want to use Cisco VPN clinet to connect and can do so, but cannot ping on the LAN or connect to the servers...Need help wih the configurations as we are novices perhaps..Can someone look at the attached config. and see if we overlooked something...Thanks



Correct Answer by acomiskey about 9 years 2 months ago

Change your pool to something outside of 192.168.2.0/24.


ip local pool vpnpool 192.168.x.60-192.168.x.63


Then add a nat exemption acl for this network.


access-list nonat permit ip 192.168.2.0 255.255.255.0 192.168.x.0 255.255.255.0

nat (inside) 0 access-list nonat


Then, also change your split tunnel acl to reflect the new pool


access-list SplitTunnel permit ip 192.168.2.0 255.255.255.0 192.168.x.0 255.255.255.0

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
acomiskey Thu, 04/17/2008 - 06:03
User Badges:
  • Green, 3000 points or more

Change your pool to something outside of 192.168.2.0/24.


ip local pool vpnpool 192.168.x.60-192.168.x.63


Then add a nat exemption acl for this network.


access-list nonat permit ip 192.168.2.0 255.255.255.0 192.168.x.0 255.255.255.0

nat (inside) 0 access-list nonat


Then, also change your split tunnel acl to reflect the new pool


access-list SplitTunnel permit ip 192.168.2.0 255.255.255.0 192.168.x.0 255.255.255.0

Actions

This Discussion