Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco VPN Client 3.5.x integrated firewall 1

Status
Not open for further replies.

schazz

MIS
Oct 4, 2001
4
0
0
US
We have a Cisco VPN Concentrator 3000 using an address pool for VPN client assignment.
All groups require a firewall.
The firewall policy is pushed to each VPN client using CPP.

When the 'Stateful Firewall' option is enabled on the VPN client, we are unable to ping from the local LAN to the VPN client. Upon disabling this option, pings are successful. (We are able to ping the opposite way regardless of setting)

Is there any way to enable the client 'Stateful Firewall' and still be able to access the VPN client from the LAN?
 
Using CPP, you should be able to configure the firewall policy such that the remote VPN client responds to ICMP (Ping) requests.
 
The Cisco VPN client ships with a striped down version of Zone Lab's ZoneAlarm host firewall product. You cannot alter this firewall configuration. It is statically set to not allow any incoming traffic to the vpn client, *UNLESS* the traffic was initiated from the vpn client itself. You cannot connect to the vpn client from your LAN with the firewall in place.
 
Thanks.
I had hoped that we could somewhat protect the client PC while no tunnels exist AND be able to manage it from the LAN while the VPN tunnel is established.

Maybe in a future release.....
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top