cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
0
Helpful
2
Replies

Once connected to remote site VPN users can't go anywhere

UCcomp2007
Level 2
Level 2

We have setup a remote site IPSEC vpn on Cisco ASA 5520's. When users connect via AT&T Air-cards, they are able to connect to VPN and get to internal servers and the internet (no split tunneling being used). When users are on local area network at home (behind wireless access points, firewalls) or in the office on LAN they can connect, but can't go anywhere (can't ping any internal server or internet).

We have verified that their is no private addressing conflict.

Does anyone have an idea of what could be causing this?

Thanks in advance,

1 Accepted Solution

Accepted Solutions

JORGE RODRIGUEZ
Level 10
Level 10

Try enabling NAT-T on asa, have them try after you enable it.

PIX/ASA 7.1 and earlier

pix(config)#isakmp nat-traversal 20

PIX/ASA 7.2(1) and later

securityappliance(config)#crypto isakmp nat-traversal 20

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#Solution1

Regards

Jorge Rodriguez

View solution in original post

2 Replies 2

JORGE RODRIGUEZ
Level 10
Level 10

Try enabling NAT-T on asa, have them try after you enable it.

PIX/ASA 7.1 and earlier

pix(config)#isakmp nat-traversal 20

PIX/ASA 7.2(1) and later

securityappliance(config)#crypto isakmp nat-traversal 20

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#Solution1

Regards

Jorge Rodriguez

Thanks Jorge. That resolved my issue.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card