- Gold, 750 points or more
The reply from the VPN Concentrator is not getting to the Client, and the Client is retransmitting the connection request. The problem is usually an Access Control List (ACL) or routing issue.
Verify that the Internet Security Association and Key Management Protocol (ISAKMP) port -- User Datagram Protocol (UDP) 500 -- is not blocked by an ACL, and verify that routing to the workstation from the VPN Concentrator is correct.
If you are using IP Security (IPSec) over UDP or IPSEC over Transport Control Protocol (TCP), make sure those settings have been turned on for both the Client and Concentrator.
You can configure the Concentrator to use IPSec over UDP and IPSec over TCP at the same time. The VPN Client can use either one, but only one at a time. It must manually select which one it is going to use.
To configure IPSec over TCP, select Configuration > System > Tunneling Protocols > IPSec > NAT Transparency. Make sure that IPSec over TCP option is checked.
To configure IPSec over UDP, select Configuration > User Management > Groups > Group Name > Client Config. Make sure that IPSec over UDP option is checked.
For further configuration information, refer to the these documents:
- For IPSEC over UDP: Configuring NAT Transparent Mode for IPSec on the VPN 3000 Concentrator
- For IPSEC over TCP: Configuring IPSec over TCP on a Cisco VPN 3000 Concentrator with VPN Client Release 3.5