cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
383
Views
0
Helpful
5
Replies

Need help with remote access vpn

mjsully
Level 1
Level 1

I have a PIX 501 with an active L2L tunnel on it. I have also just added a remote access vpn, in which I'll be connecting to the inside network with the Cisco vpn client using local authentication. I've got it setup so I can authenticate and get an assigned ip address, but I cannot ping across to the inside network anywhere. I have sysopt enabled so that is not the issue. I'm not sure if something is conflicting with the L2L tunnel or not. I've attached the config and broken it up to best describe what its doing. Can someone please advise on to what the issue could be?

5 Replies 5

acomiskey
Level 10
Level 10

Add...

isakmp nat-traversal

That did it!!

Can you explain why that is needed? Appreciate the fix!

Hi

During the phase II negotiation there is seperate unidirectional ESP session between PIX and the VPN client.So when there is NAT involved in the set up there are issues due to the translation .

To overcome those issues NAT-T is used.

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1732264

HTH

Ullas

That's where I'm confused. I'm not NATn'g anything.

Hi, at the client side has been nat, the client connect to VPN server.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card