Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco VPN 3.6 disrupts Network/file sharing

Status
Not open for further replies.
Jun 24, 2002
19
0
0
US
W2K Server
30 clients XP Pro/W2k Pro
DSL connection

I have seen this issue posted several times, but all efforts on my part have had no sucess.

Without the VPN connected, clients can share files, print, access server, and internet. Once VPN is connected all access to LAN is disabled. File sharing, printing, and seeing the server or other clients no longer works. Internet access still connects.

SOMETIMES - If a client prints or accesses the server BEFORE logging onto the VPN the connection will hold after VPN is connected. Again that is only sporatically.

The Server has AD, and DNS. IP addresses are assigned Dynamically.

I am aware that once the VPN is on it takes over as DNS and WINS server. I'm sure all network traffic is being sent to the other end of the VPN. I cannot however alter settings on that end of the VPN as I'm not in control of that Network.

I have tried so many things that I forget them all but they include:
selecting "Allow LAN access" through VPN properties
using IMHOSTS file
Force Kerberos to Use TCP Instead of UDP (actually Server and clients tested were already set at "1")

any suggestions would be great, as I am preparing a nooce out of my old RJ-45 cables. Bob C. I/T Department WYSAC
 

What do the VPN clients connect to ? Cisco Concentrator ?

On the concentrator in the client config tab of the Base Group or Client Group you can set parameters for split tunneling. You might currently have it to "tunnel everything".

The 3 options are :

Tunnel Everything: Send all traffic through the tunnel

Allow the networks in the list to bypass the tunnel: The VPN Client may choose to send traffic to addresses in this list to the client's LAN. Send all other traffic through the tunnel. NOTE: This setting only applies to the Cisco VPN Client.

Tunnel networks the in list: Send traffic to addresses in this list through the tunnel. Send all other traffic to the client's LAN.

If you select only tunnel networks in the list and build yourself a network list containing just the IP addresses of the remote end of the VPN and then in theroy the rest of the traffic will go to the local LAN and your servers.

 
Not sure what you mean by:
"client config tab of the Base Group or Client Group". I have no such settings that I can find on the client on my workstation. Are these settings in the client? If so could you point them to me. If not I don't know if I can access the Server settings. Bob C. I/T Department WYSAC
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top