Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Can't communicate with network until client is pinged from VPN concentrator

We have Cisco 3005 VPN concentrator and the client is 3.5.2. We are seeing a strange issue where we can get authenticated just fine, but no data flows through the tunnel until we ping the client's assigned IP address from the concentrator. Has anyone seen this before?

5 REPLIES
Silver

Re: Can't communicate with network until client is pinged from V

No.

There must be some sort of routing issue. Can the client at least ping the private interface of the concentrator when connected?

Is it a software or hardware client?

Have a look at the routing information on the concentrator once the client is connected and could not pass traffic, and compare it when the client is passing traffic.

Regards,

New Member

Re: Can't communicate with network until client is pinged from V

Thanks for the message.

We cannot ping the private interface until we ping out from the 3005 to correct the situation. This is a software client and the routing information remains the same regardless of whether it is working or not. This is looking more like an ARP situation.

Mikee

New Member

Re: Can't communicate with network until client is pinged from V

Hi I have had the same problem, We had a pix firewall in the network aswell, What happened was the pix kept picking up the packet dest for the Concentrator, it all came down to ARP, we add static ARP entries into our router and it worked ok. But still not sure as to why the pix was doing this!!

Hope this helps

Regards

New Member

Re: Can't communicate with network until client is pinged from V

You hit it right on the head. It is an ARP issue (I checked the router ARP table). Do you know the syntax for adding an ARP entry to the router? I can't seem to find it on-line

Thanks!!!

Silver

Re: Can't communicate with network until client is pinged from V

Actually, what you have to do is to disable proxy arp on the pix interface where the private of the concentrator is connected.

sysopt noproxyarp 'ifname'.

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_61/cmd_ref/s.htm#xtocid22

That should fix the arp issue.

Regards,

108
Views
0
Helpful
5
Replies