I am in need of some help regarding a Cisco PIX 506E. I have a tunnel between two office's that works perfectly. Now, I want to create another VPN connection for remote access using the Cisco VPN Client. I cannot access any network resources. My running-config is below with personal stuff omitted. Can anyone see the problem or provide any insight.
I can connect with the client but can't ping anything. If I add the command (
crypto dynamic-map outside_dyn_map 40 match address outside_cryptomap_dyn_40) it won't connect and the clients error is (
136 16:20:48.654 02/19/07 Sev=Warning/3 IKE/0xA3000029
No keys are available to decrypt the received ISAKMP payload)
My running config -
object-group network office
network-object 192.168.0.0 255.255.255.0
object-group network mct
network-object 192.168.210.0 255.255.255.0
network-object 192.168.211.0 255.255.255.0
network-object 192.168.212.0 255.255.255.0
network-object 10.2.0.0 255.255.0.0
access-list compiled
access-list ec_vpn permit ip object-group office object-group mct
access-list ec_vpn permit ip 192.168.0.0 255.255.255.0 192.168.10.0 255.255.255.0
access-list ec-client-group_splitTunne
lAcl permit ip 192.168.0.0 255.255.255.0 192.168.10.0 255.255.255.0
access-list outside_cryptomap_dyn_40 permit ip 192.168.0.0 255.255.255.0 192.168.10.0 255.255.255.0
nat (inside) 0 access-list ec_vpn
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
access-group inside in interface inside
floodguard enable
sysopt connection permit-ipsec
crypto ipsec transform-set 3des-set esp-3des esp-md5-hmac
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto dynamic-map outside_dyn_map 40 set transform-set ESP-3DES-MD5
crypto map ecorner-mct-vpn_trans_map 20 ipsec-isakmp
crypto map ecorner-mct-vpn_trans_map 20 match address ec_vpn
crypto map ecorner-mct-vpn_trans_map 20 set peer X.X.X.X
crypto map ecorner-mct-vpn_trans_map 20 set transform-set 3des-set
crypto map ecorner-mct-vpn_trans_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map ecorner-mct-vpn_trans_map interface outside
isakmp enable outside
isakmp key ******** address X.X.X.X netmask 255.255.255.255
isakmp identity address
isakmp keepalive 60
isakmp nat-traversal 20
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
isakmp policy 30 authentication rsa-sig
isakmp policy 30 encryption des
isakmp policy 30 hash sha
isakmp policy 30 group 1
isakmp policy 30 lifetime 86400
isakmp policy 40 authentication pre-share
isakmp policy 40 encryption 3des
isakmp policy 40 hash sha
isakmp policy 40 group 2
isakmp policy 40 lifetime 86400
isakmp policy 50 authentication pre-share
isakmp policy 50 encryption aes
isakmp policy 50 hash md5
isakmp policy 50 group 2
isakmp policy 50 lifetime 86400
isakmp policy 60 authentication pre-share
isakmp policy 60 encryption aes
isakmp policy 60 hash sha
isakmp policy 60 group 2
isakmp policy 60 lifetime 86400
vpngroup ec-client-group address-pool ec-client-pool
vpngroup ec-client-group dns-server X.X.X.X
vpngroup ec-client-group wins-server 192.168.0.104
vpngroup ec-client-group default-domain DOMAIN
vpngroup ec-client-group split-tunnel ec-client-group_splitTunne
lAcl
vpngroup ec-client-group idle-time 1800
vpngroup ec-client-group password ********
Start Free Trial