cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
582
Views
0
Helpful
4
Replies

Cant PING servers on the remote LAN form a VPN Client

Tebogo Langa
Level 1
Level 1

I cant ping anything on the inside interface of a pix 515 from a VPN client.

4 Replies 4

Olivier Jessel
Level 1
Level 1

Hi,

Have you checked you have correct ACL for traffic from VPN pool to inside subnet, and correct (No-)NAT entries in both way?

More, the split-tunneling ACL is matching your inside subnet and your vpn pool ?

CCIE #44658

This is what I have done so far.I can connect to the pix but I cant ping the inside hosts.I dont need split tunneling.

access-list client-vpn permit ip 172.16.48.0 255.255.255.248 17.1.1.0 255.255.255.240

ip local pool client-vpn-pool 17.1.1.1-17.1.1.14

nat (inside) 0 access-list client-vpn

jmia
Level 7
Level 7

Hello Michael,

You need to enable NAT Traversal on your PIX for ISAKMP i.e. in config mode...

isakmp nat-traversal

Save with wr m

Hope this helps and please rate posts.

i am runnning ver 6.1(3).The firewall doesnt want to take that command.

Review Cisco Networking products for a $25 gift card