08-06-2008 03:14 PM - edited 03-03-2019 11:03 PM
Hi Guys,
I have configured VPN and want to use internet via same link. I can ping any public ip from router, but can't ping (get many loses) during ping from inside host.
I have attached my config file..
I hope you guys will help me finding my configuration bug.
08-06-2008 04:10 PM
Your configuration looks perfect to me.
You are implementing a split tunnel. IPSec tunnel traffic sourced from vlan 1 and destined for the 3 subnets in your ACL does not get NATed, but Internet traffic does.
The crypto policy looks typical.
You rely on a recursive lookup to find the route to the IPSec peer.
The NATing looks typical, too.
Am I missing anything?
Can you do a "sho ip nat trans*" and run a PING test to an Internet host and source the vlan and post the results?
Is tunnel traffic OK?
Victor
08-06-2008 04:49 PM
Thanks for reply,
The tunnel is perfect, and is in operation for last 15 days with no issue.
The NAT translation works fine. I even get some ping packet reply from google.com but just 1-5% reply, rest are lost. I will be posting nat and ping reply shortly.
08-06-2008 06:51 PM
?
08-07-2008 03:42 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: