Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

The Cisco VPN Client is able to connect to the PIX Firewall but not able to pass traffic

Core issue

One likely explanation is that the same Access Control List (ACL) is being used for NAT bypass (NAT 0) as well as for crypto map.

If the same ACL is bound with NAT 0 as well as the LAN-LAN crypto map entry, then this behavior is expected because the NAT 0 ACL also has the VPN client pool configured as the destination. When the crypto map is checked for this traffic, it finds a match with the LAN-to-LAN tunnel and is never sent out through the dynamic crypto map. The static crypto map takes the precedence over the dynamic crypto map. The PIX attempts to encrypt the traffic using the static crypto map and sends out to the relevant peer, as shown:

access-list myvpn permit ip
nat (inside) 0 access-list myvpn
crypto map mymap 10 ipsec-isakmp
crypto map mymap 10 match address myvpn
crypto map mymap 10 set peer
crypto map mymap 10 set transform-set myset

To add clients, issue these commands:

ip local pool mypool
access-list myvpn permit ip

Now, the myvpn ACL is configured for the remote LAN-to-LAN network, as well as the VPN client pool. Whenever there is some traffic from the network for the network, it goes to the peer rather than the VPN Client.


To resolve this issue, create another ACL for NAT 0. Do not use the same ACL for NAT 0 and the crypto map.

Version history
Revision #:
1 of 1
Last update:
‎06-22-2009 03:33 PM
Updated by:
Labels (1)