09-16-2005 06:14 AM
Hi all,
I setup few vpn acces on my pix 506, all theses access are dedicated to roaming users who used the cicsco vpn client.
Each user have his own ip local pool (one per vpngroup and one address per ip pool), we have a problem because when the user drop his vpn connection the ip address of the local pool is "still in use" in the pix and if user user try to connect he is rejected because there is no availble ip address for him.
Do you know why these ip address stay "in use"
Thanks in advance for your help.
olivier
09-16-2005 08:04 AM
try the command "isakmp keepalive"
09-18-2005 09:34 AM
Don't have an answer to your question other than the timeout probably hasn't kicked in yet. Probably the timeout that's connected with the isakmp command (isakmp keepalive
I'm more interested in our how got your basic set up going -- I came into the forums to see if I could find some help.....and the first message I read was yours. :-)
I'd like to set up an addtional vpngroup (we've been using one group for a while now), and I'm having problems getting the pix to accept the command: isakmp client configuraiton address-pool local xxxx1 outside. It says there's already an address-pool connected to that interface and I'm to remove it. Of course, that'll break all current access, so I'm reluctant to do so without confidence I'll be able to put them both in afterwards.
Oh. We're using a pix 515 with 6.3(3).
Might you have any suggestions? Any help you can offer will be appreciated!
Charlotte Sawyer
09-18-2005 07:19 PM
we haven't been using that command, however we've got multiple vpngroups working fine.
ip local pool ippool1 10.0.0.1-10.0.0.10
ip local pool ippool2 172.16.8.1-172.16.8.10
vpngroup vpn1 address-pool ippool1
vpngroup vpn1 split-tunnel 101
vpngroup vpn1 idle-time 1800
vpngroup vpn1 password ********
vpngroup vpn2 address-pool ippool2
vpngroup vpn2 split-tunnel 102
vpngroup vpn2 idle-time 1800
vpngroup vpn2 password ********
09-19-2005 08:23 AM
Thanks for the info!!!!
So do you serve dns and/or wins info to your clients?
09-19-2005 03:50 PM
i do dns but not wins
vpngroup vpn1 dns-server
i believe you can put 2 servers with the command
09-19-2005 03:57 PM
Thanks! I'll give that a try! :-)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide