Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN - MRTG serious problems

Status
Not open for further replies.

theodorg

Programmer
Sep 10, 2002
3
IS


I recently set up a VPN server on a pix 501 box and everything seemed to work fine and I am able to connect to the VPN server with my Cisco VPN client 3.5.1 and I am able to have full contact with the network on the inside interface of the pix. I am connecting to the VPN server from an ADSL connection from work from a routable IP and everything works great. I dont seem to have any problems with the VPN client at work.

The problem arises when a person that I was setting this server up for tries to connect to the server via his GPRS connection from his laptop. He can connect to the VPN server and everything seemingly worked and he can even ping addresses on the inside interface on his network but when he tries to connect via tcp he is unable to get through, For example when he tries to map a drive on the fileserver at work he gets this error: (network error 5 has occurred - access is denied). And with other connections such as telnet, etc it just halts and eventually times out.

He is using the exact same client I am using with the same configuration and all the IP information are correct. In the VPN client the packets seem to be receieved on his box but they are all apparently discarded(I dont have physical access to this machine)and I dont understand why because it has successfully negoiated keys and everything seems to be exactly like at work but for some reason the packets get discarded ;-/. The machine that he is using is running Windows XP and firewall on the ppp interface has been disabled. I can't see what the problem is and this is confusing!

The person also gets these messages in the error log:
"Received malformed message or negotiation..." According to a previous thread on this site a solution was in the global line, "global (outside) IP netmask 255.255.255.255" This has been done and it had no effect. the MTU on the pix is set at 2000 but I dont know for the client, maybe if he tries to lower the MTU that might work but if anyone here has any ideas I would greatly apreciate any assistance you could offer because this is a serious problem that I can't get my head around.

Thanks alot!!

Theodor
 
I have no idea why but I said MRTG in the subject line for this thread. I was obviously thinking about a totally different project that was in no way related. I was of course talking about GPRS.

thanks,
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top