cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
641
Views
5
Helpful
8
Replies

IOS Router VPN - Client cannot connect to all subnets

infosateng
Level 1
Level 1

Hello

I have setup a IOS Router VPN that uses IPSec with Radius Authentication. I am using Cisco VPN Client 4.8. The connection and the Authetication work great, but the client cannot connect to all Subnets. I can sometimes can connect to a specific host in a subnet, but not others.

For example I have another router with a number of sub-interfaces on it, and I can ping only 80% of these sub-interface addresses. Any Help would be most greatful.

8 Replies 8

Ivan Martinon
Level 7
Level 7

you are not using any split tunnel so there should be no reason why the traffic should not flow from client to router and back, you could try to enable reverse-route under the dynamic tunnel and see if that helps.

also when the client cannot reach those networks, can your router reach them?

Ok Thanks, I give that a go.

Yes, the router can connect to everything

Hello

I've added the reverse-route command to the Dynamic Tunnel and the problem is still the same.

Do me a favour, go ahead and create a loopback interface on the router, with an ip address that is not on the local subnet of your router or any other subnet behind it, then once it is created ping those subnets the client is unable to ping sourcing the ping from the loopback interface, are you getting replies?

Hello

Well that was interesting, I got the same problem. I can ping some addresses, but not all. Even if ip addresses are sub-interfaces on the same router.

If you both, try a traceroute from those ip address(es) that you can reach from the client, to the vpn client assigned address from the pool, do you see it going to the vpn server?

Yes, I see what the problem is. We have a couple of Core routers and doing a traceroute from the offending devices it stopped at the Secondary. I've add a static route and all is well.

Thanks for you help, I can now see the wood from the trees.

Awesome! do rate useful posts

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: