Hi,
Cant find any reason why this happens but here goes....
VPN3005 Concentrator & SSLVPN
Everything is configured and running, applications, intranets, web services ect....
but when i want to browse the local LAN the strangest thing happens.
All shares on the network are availiable except...
its great for technical people to use for remote sessions.
if you intend to have users then i would strongly suggest using web based applications for them, as the interface for ssl vpn is still quite dated.
i am sure cisco will catch up when they sort out the security first.
Windows XP and windows 2000 server have different cache password policies, thats why xp doesn't remember passwords.
Microsoft look at this from a security point of view.
Have you used IAS to authenticate the users on the AD domain using radius, this seems to pass the user details from the vpn...
I have a simular problem, when using the vpn 3.x client, from a PC that connects directly to the internet, they can vpn into the LAN, but when using the same method via a 1603 ISDN router that dials the internet, a connection is made but no traffic is sent through the tunnel and i lose all...
You can you any IP range you like as long as it doesnt conflict with the inside network subnet, so 192.168.5.x would be fine, the pix will route to your 192.168.x.x network.
for 3des, you need to change
crypto ipsec transform-set dialinvpn esp-des esp-md5-hmac
to
crypto ipsec transform-set...
If your teleworker is setting up a domain, you could use trusting between them, this will authenticate both users on both domains, and keep AD in place
You need to add static routes using telnet because the web config editor cannot add static routes to IF4 (the vpn tunnel) using this method you can send traffic through the vpn tunnel and onto another router/device
Yes i setup a LAN-LAN Dialer Profile and managed to get a vpn connection, however not all traffic is allowed through the tunnel, the web config is the first place to setup, then you need to telnet into the router and add the static commands to the vpn interface, dont work using the web config...
SMS uses its own accounts to create these shares, and does not allow manual creation as far as i am aware, therefore it sounds like a uninstall and reinstall to clear this up, how that will fit with your child sites, i am not sure of.
I had the same problem, and found that SMS will bring in the clients, it just takes time, some of my sites over a WAN can take upto a week to be fully installed. Just make sure that the clients are running the SMS login script, this seems to speed things up a little.
You could get sms to login and set the local policy of the windows 2000 client to logoff after a set period of time, or use the rundll (can remeber the full command, see microsoft.com) command to logoff the user using the remote tools within SMS, but if you are going to use remote tools you may...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.