Are using a hardware VPN or a Pix with the VPN function enabled. If it is the Pix type then you would have to enable split tunneling. Cisco states it something like "the Pix will not send packets out the same interface it received them on" or something like that.
And yes the split-tunnel fonction is enable in my VPN configuration...
When I'm connected to the VPN, I can't go anymore on the Internet...
Is it a problem with my vpn config???
Here's my VPN config
crypto ipsec transform-set myset esp-des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set myset
crypto map mymap 10 ipsec-isakmp dynamic dynmap
crypto map mymap interface outside
isakmp enable outside
isakmp identity address
isakmp client configuration address-pool local test outside
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
vpngroup toto address-pool test
vpngroup toto dns-server 172.16.244.3
vpngroup toto wins-server 172.16.244.3
vpngroup toto default-domain toto.com
vpngroup toto split-tunnel 101
vpngroup toto split-dns test02.toto.com test01.toto.com test03.toto.com test04.toto.com
vpngroup toto idle-time 1800
vpngroup toto password ********
telnet timeout 5
ssh timeout 5
vpdn group test accept dialin pptp
vpdn group test ppp authentication pap
vpdn group test ppp authentication chap
vpdn group test ppp authentication mschap
vpdn group test ppp encryption mppe 40
vpdn group test client configuration address local test
vpdn group test client configuration dns 172.16.244.3
vpdn group test client configuration wins 172.16.244.3
vpdn group test pptp echo 60
vpdn group test client authentication local
vpdn username testvpn password *********
vpdn enable outside
> ip local pool test 172.16.244.100-172.16.244.130
Change it to something else, like:
ip local pool test 192.168.111.1-192.168.111.30
> access-list 101 permit ip any any
This is the problem.
Change it to something like:
access-list 101 permit ip 172.16.244.0 255.255.255.0 192.168.111.0 255.255.255.0
You can then verify the split-tunnel by double clicking the yellow icon at the remote vpn client, and checking the "statistics" tab.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.