Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Cannot connect to VPN on PIX 501 without public IP Address

I am having an issue connecting to our PIX at work from computers that are NATed. For example, if I try to connect to our PIX with the Cisco VPN client from my home behind my router, it will not connect, and gives me an error 412 saying it cannot reach the destination. However, if I plug my computer directly into my cable modem, and obtain a public IP Address, I can connect without problems. I have been able to duplicate this at other locations. In each location, the VPN passthrough on the home office router is enabled. Our PIX 501 sits behind a Siemens router with all ports and protocols forwarded to it.

We have some clients that I connect to via VPN that have PIX 501 and I can get to them from within my home office just fine. I'm not sure that it's at the home office end.

Any help with would be greatly appreciated.

3 REPLIES
New Member

Re: Cannot connect to VPN on PIX 501 without public IP Address

Our PIX configuration is attached.

Gold

Re: Cannot connect to VPN on PIX 501 without public IP Address

try applying the command "isakmp identity address".

further, may i suggest that not to overlap the vpn client pool and the pix inside subnet. odd issue may happen.

New Member

Re: Cannot connect to VPN on PIX 501 without public IP Address

I've tried adding this command and clearing up the overlap thank you, but unfortunately still no joy.

252
Views
0
Helpful
3
Replies