Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cannot access Cisco VPN through ISA

Status
Not open for further replies.

UTTech

MIS
Oct 11, 2000
245
US
Small Business Server 2000
ISA 2000 with Proxy enabled
Cisco PIX Firewall 501e

We are trying to setup VPN with another site with Cisco PIX but running into problems with ISA.

From the server, I am able to ping the other VPN site.
I cannot ping the VPN from a workstation.

Workstation IP is 192.168.0.3.
Server has 2 NICs.....1 is 192.168.0.1 and 2 is 192.168.1.4
192.168.1.4 is connected to the PIX (192.168.1.1).
 
Update:

Small Business Server 2000
ISA 2000 with Proxy enabled
Cisco PIX Firewall 501e

We are trying to setup VPN with another site with Cisco PIX but running into problems with ISA.

I can ping to the other VPN site from the server and the workstation. The problem is that when I ping from the workstation, the server translates the workstation IP (192.168.0.3) to the server IP (192.168.1.4). I do not want the address to be translated when connecting to this specific IP address. Where can I modify or disable the NAT translation?

Workstation IP is 192.168.0.3.
Server has 2 NICs.....1 is 192.168.0.1 and 2 is 192.168.1.4
192.168.1.4 is connected to the PIX (192.168.1.1).
 
Normally you can only ping remote destinations from the ISA Server itself.

For VPN to work, you need to define packet filters and allow for PPTP to traverse the ISA firewall. Note that this will only work for firewall and securnat clients.

Cheers
Knutern
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top