Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco VPN Software/Concentrator Question

Status
Not open for further replies.

ts8586

MIS
Nov 28, 2004
92
US
Hello, I have a remote user that needs to access the network from home. We'll call it Network B, 10.6.x.x
He has the Cisco VPN Client software on his laptop, and he can establish a tunnel to Headquarters Network A, 10.1.x.x without a problem. However, that does him no good since Networks B-Z aren't accessible.

What would be your troubleshooting steps regarding this problem? Thanks for any helpful advice.

 
A static route from the vpn assigned pool to whatever they want to reach. What kind of equipment?

Burt
 
A 3005 Concentrator. I'm going to have to get the static route info. I did a search and that came up.

 
I assume networks B-Z are on his home network? If so you would have to configure split tunneling. Although for security reasons I dont recommend it.
 
Not sure if this applies to the Cisco VPN, but in Netscreen on the remote client where you state 10.6.x.x is the network range, change that to 0.0.0.0 this allows access to all ranges.

Cheers,

Steff
 
Brain,

No, networks B-Z are offices in different cities. "A" is headquarters.



SteffK, I don't think that option is set on the client, but it may be on the Concentrator. Thanks for the idea.

 
Okay I was confused because you refered to the remote network as Network B. How are the other networks connected to A?
 
ts8586,

If that is only available in the Concentrator, what about changing the policy?
 
Boy, I sure left a lot of details out. Sorry about that. Sites B-Z come back to HQ (A) via their own VPN tunnels. The way it was set up several years ago, is that if a user needed access to Site D for example, they'd connect to one of the Concentrators at HQ, then hop over to Site D. It used to work, now it doesn't. We were told that it would be easier to administer this way, rather than have to set up the users on the Pix 506E's at the remote sites.

 
An ASA supports Hub and Spoke VPNs like that, but I am not sure the concentrator does.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top