cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1617
Views
14
Helpful
20
Replies

PIX 506E VPN Cant Ping

rgeno
Level 1
Level 1

Got a PIX 506E configured for VPN Client Access.

VPN Client connects however cannot ping anything on the LAN.

Confirmed config with other Cisco Docs and is okay.

Please help

20 Replies 20

Done that and still no luck....unable to ping hosts.

nat traversal suggestion by jorge just fits the issue but you have it.

Couple of things to check,

Make sure the PC, which connects VPN and acquires 192.168.10.x address, doesnt have an IP address locally assinged to its NIC within same subnet of 192.168.10.x

Try connecting via x port instead ping to check connectivity. For example enable remote host for Remote Desktop, run netstat -an and make sure 3389 is listening, then from VPN client, run telnet remoteclientIP 3389 and wait to get a blank screen.

Right-click VPN icon in right-bottom, click statistics then route details tab. Make sure the clients you try to reach are listed in right pane.

Save your config and reload firewall

In clientside, open up VPN Client Gui, Click log then click enable. Then click log window. Try pinging somewhere, then paste here the logs you see in that window

Run ASDM and enable its builtin syslog, catch some syslogs related to the traffic and paste here

Regards

Did all that and still no good!

Telnet via port 3389 - no connection.

Routes - are visible in the route details.

Log windows shows nothing.

Unable to ping hosts

Try 3 things,

1) Make sure the VPN Client has IPSEC Over UDP/NAT-T enabled, its there by default, but someone could have removed the check there.

2) Are you sure you trying to RDP to 172.16.1.3 or 172.16.1.15 (FIFTEEN) and not 172.16.1.51? Because 172.16.1.51 is not in your Split Tunnel ACL.

3) If you do 'route print' on the Windows box after the VPN connection, do you see 172.16.1.3/.15 are directed through VPN tunnel?

Regards

Farrukh

Yes done (1)

(2) - it is 172.16.1.15 not .51

(3) - yes they are directed through the tunnel

Does it still not work? Does the VPN Client tell you that Transparent Tunneling is active, ON the status tab?

Regards

Farrukh

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card