Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 501 and the Remote VPN Client

Status
Not open for further replies.

Laylobrown

Technical User
Mar 7, 2007
63
US
My vpn client connects perfectly to the PIX 501 but I am unable to ping anything at the host site. The dhcp subnet at the host site is 192.168.0.2-192.168.0.129 and the vpn range I assigned was 192.168.0.130-192.168.0.140. My vpn client recieves 192.168.0.130 but I cannot reach any device on the host network.

During the vpn wizard it said that by leaving a host network option blink it will by default leave the internal network open to the vpn client. Am I missing something?

I will need to run over to the host site and get the conf files if needed but an example or link would work fine at the moment.

Thanks

Laylobrown, learning a lot from this site.
 
I'm using a vpn client 4.8 and in the transport it has 'enable transparent tunneling' and the ipsec over udp (nat/pat) option is selected by default.

it also has an option to use ipsec over tcp but the default port is 1000.

I can make the vpn connection but cannot ping the host site.

the host subnet is 192.168.0.0 and i made the subnet for the vpn remotes 192.168.1.0 this time.
 
Here is the log file from the remote client

Cisco Systems VPN Client Version 4.8.00.0440
Copyright (C) 1998-2005 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 5.1.2600 Service Pack 2
Config file directory: C:\Program Files\Cisco Systems\VPN Client\

1 09:37:55.906 06/15/07 Sev=Warning/3 GUI/0xA3B0000B
Reloaded the Certificates in all Certificate Stores successfully.

2 10:22:37.515 06/15/07 Sev=Warning/3 CM/0xA3100027
Adapter address changed from 10.10.0.100. Current address(es): 172.168.0.2.

3 10:22:37.515 06/15/07 Sev=Warning/3 IKE/0xE3000068
Failed to send 68 bytes to 66.83.21.66, error = 0xFFFFFFF0

4 10:22:37.515 06/15/07 Sev=Warning/3 IKE/0xE3000068
Failed to send 76 bytes to 66.83.21.66, error = 0xFFFFFFF0

5 10:22:37.515 06/15/07 Sev=Warning/2 CVPND/0xA340000E
Failed to get adapter index.

6 10:22:37.515 06/15/07 Sev=Warning/2 CVPND/0xA340000E
Failed to get adapter index.
 
Here is the configuration information on the pix. I can connect with the vpn client but cannot ping or access anything at the host site.



Written by enable_15 at 10:47:44.250 UTC Fri Jun 15 2007
PIX Version 6.3(5)
interface ethernet0 auto
interface ethernet1 100full
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname pixfirewall
domain-name ciscopix.com
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names
access-list mhbvpn_splitTunnelAcl permit ip any any
access-list inside_outbound_nat0_acl permit ip any 10.20.0.0 255.255.255.248
access-list outside_cryptomap_dyn_20 permit ip any 10.20.0.0 255.255.255.248
pager lines 24
mtu outside 1500
mtu inside 1500
ip address outside dhcp setroute
ip address inside 192.168.0.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
ip local pool mhbvpn 10.20.0.1-10.20.0.5
pdm logging informational 100
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list inside_outbound_nat0_acl
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout sip-disconnect 0:02:00 sip-invite 0:03:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
http server enable
http 192.168.0.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
sysopt connection permit-ipsec
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20
crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map outside_map interface outside
isakmp enable outside
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
vpngroup mhbvpn address-pool mhbvpn
vpngroup mhbvpn split-tunnel mhbvpn_splitTunnelAcl
vpngroup mhbvpn idle-time 1800
vpngroup mhbvpn password ********
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd address 192.168.0.2-192.168.0.129 inside
dhcpd lease 3600
dhcpd ping_timeout 750
dhcpd auto_config outside
dhcpd enable inside
terminal width 80
Cryptochecksum:90ec4959ce23178d0110f5f2e679672a
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top