Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Can't run Mobile VPN client from behind a firewall

Status
Not open for further replies.

BigFinn

MIS
Aug 28, 2003
64
0
0
GB
I need to connect to our PIX at work via VPN client. This works fine when my PC is connected directly to the Internet (cable modem), but refuses to work when my PIX at home is set up in between the client PC and the cable modem.

When VPNing 'through' the PIX, the VPN client comes up, the padlock closes and DPD keepalives travel back and forth up the tunnel (I can see them in the logs). It appears to be working correctly.

I can also see the change in my client PC when the VPN client starts up (I get an IP address for the CISCO VPN adapter, the VPN group WINS server IP address is configured) but I cannot send any traffic to the LAN at work. I can't ping anything, not even the WINS server I can see dynamically configured in the IP properties on the client PC.

Has anyone had similar experience?

Kind Regards

BF
 
You probably do need NAT traversal. Another problem could be that you are using the same IP address range at work and at home, that will cause problems also.

Look in status-statistics-route details on your VPN client, are the remote LANs there?

 
Actually, the stats route details always shows 0.0.0.0 when im connected.

Its the sho isakmp or sho crypto sa PIX commands that help diagnose the tunnels.

(Get connected to the PIX via SSH first)



 
I had similar problem
isakmp nat-traversal 20 on the PIX did solve problem,
and you need to open udp/4500 port on the gateway to Internet.

Hope it would help.
 
Hi NickDJ, others,

thanks for the answers.

Does that udp/4500 port need to be opened on the PIX at the corporate LAN where I'm trying to connect to, or on my PIX standing in the way?

BF
 
sysopt connection permit-isakmp" does it for the pix
other routers in front may need an ACL
or a simple "IPSec passthrough" selection for you

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top