Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PPTP VPN - Ping some hosts but not others

Status
Not open for further replies.

JezEling

IS-IT--Management
Mar 22, 2004
127
GB
Hi all,

I am looking to replace my current Windows 2K VPN box and use our PIX 515 instead. I have configured the PIX for PPTP access and can connect no problem from my laptop using a dial up connection and then Tunneling into the LAN.
Once I am connected I can ping some hosts but not others I simply get a request timed out.

Does anyone know what is causing this and how I can resolve it? I have been working on this for the past week or so and it is driving me up the wall.

Thanks In Advance

Jez.
 
Your problem sounds similar to one that we have from time to time.

Is there a live ethernet card in that laptop (not attached to your LAN), does that card have an address and are the machines that you can not access on the same subnet that the card thinks it is on? If so you need to release the address from the card.
 
I have the same issue.

Do you use WINS on your network?
I think it is near impossible to get netbios name resolution to work over the vpn as I don't think the PIX will forward broadcast packets.

Make sure all your hosts are registering with your WINS server if you have one, I bet you will find that the hosts you can't ping aren't in your wins database.

if you use the ip of the host instead of name can you ping then?
 
Do the hosts that you can't ping have a default gateway of the Pix? Do they have personnel firewalls that block icmp?

Chris.


**********************
Chris Andrew, CCNA, CCSA
chris@iproute.co.uk
**********************
 
I have now resolved this issue, 100%. I have upgraded the PIX to 6.3(3), and reconfigured the pool of IP addresses I was using to auto assign to clients to a pool of IP's available on our internal network.

Eg. when I followed the Cisco guide it tells you to use a pool of 192.168.1.1-192.168.1.10. I re-configured this to legal addresses on our internal system and it all came to life.

I hope that makes sense, now it is working it is great and has allowed me to remove another Windows 2000 server from our network.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top