Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Trouble accessing gateways thru VPN

I can access a customers voice-gateways thru VPN with my home TW cable modem connection but in the office thru same VPN connection cannot. I get in to the VPN OK at office but cannot ping/telnet to devices. I do see the routes in the VPN Route Details tab, but I also do not see any return packes in the Tunnel Details tab. Any insight, I'm posting some attachements when it works vs when it doesn't...thanks for the help (newby with VPNs).

3 REPLIES
Silver

Re: Trouble accessing gateways thru VPN

Cisco Employee

Re: Trouble accessing gateways thru VPN

John,

What is the internet gateway @ your office and is your PC IP Address getting a Static Public IP Address when traffic is destined to the internet or is it Port Address Translated.

And also, what option are you using to connect to the VPN Server. Is it IPSEC, IPSEC Over UDP or IPSEC Over TCP and what is the VPN Server that you are connecting to.

If you are using IPSEC, then UDP Port 500 and Protocol 50 (ESP) are used to build the tunnel and encrypt the packets. So, if your office is set up for PATing your IP, then this set up will not work. Since Port Address Translation does not understand Protocol and your IPSEC packets will get dropped at the PATing Device.

I hope it helps.

Regards,

Arul

** Please rate all helpful posts **

New Member

Re: Trouble accessing gateways thru VPN

ajagadee,

When I am using vpnclient to connect VPN Server,I do not choose "enable transparent tunneling".Does it refer to "using IPSEC"?

According to your comment,

If you are using IPSEC, then UDP Port 500 and Protocol 50 (ESP) are used to build the tunnel and encrypt the packets. your office is set up for PATing your IP, then this set up will not work.

When packet arrive device for PATing,the device will translate source ip address only ,not the port. Why it does not work? When i must choose "enable transparent tunneling"?

Thanks a lot

martin

98
Views
0
Helpful
3
Replies