EZVPN Client can PING remote hosts but can't access SMB shares
I've recently created a VPN configuration on a 1721-K9 router running IOS (C1700-ADVSECURITYK9-M), Version 12.4(15)T7. The Windows XP SP2 client running Cisco VPN Client 5.0.04.033 can connect and ping hosts on the remote LAN but can't access SMB shares or telnet to hosts. I've turned off the Windows Firewall and removed the ACL on the router's upstream interface. The VPN client is behind another 1721 with NAT. Any ideas, anyone?
Here are the relevant portions of the IOS configuration:
crypto isakmp policy 10
crypto isakmp keepalive 20 5
crypto isakmp nat keepalive 20
crypto isakmp client configuration address-pool local VPN-pool
crypto isakmp client configuration group VPN-group
dns dns1.ip dns2.ip
access-list 150 permit ip 10.0.1.0 0.0.0.255 10.0.2.0 0.0.0.255
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...