cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
435
Views
0
Helpful
3
Replies

Cannot connect to VPN on PIX 501 without public IP Address

coolvette
Level 1
Level 1

I am having an issue connecting to our PIX at work from computers that are NATed. For example, if I try to connect to our PIX with the Cisco VPN client from my home behind my router, it will not connect, and gives me an error 412 saying it cannot reach the destination. However, if I plug my computer directly into my cable modem, and obtain a public IP Address, I can connect without problems. I have been able to duplicate this at other locations. In each location, the VPN passthrough on the home office router is enabled. Our PIX 501 sits behind a Siemens router with all ports and protocols forwarded to it.

We have some clients that I connect to via VPN that have PIX 501 and I can get to them from within my home office just fine. I'm not sure that it's at the home office end.

Any help with would be greatly appreciated.

3 Replies 3

coolvette
Level 1
Level 1

Our PIX configuration is attached.

try applying the command "isakmp identity address".

further, may i suggest that not to overlap the vpn client pool and the pix inside subnet. odd issue may happen.

I've tried adding this command and clearing up the overlap thank you, but unfortunately still no joy.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: