Advertisement

03.04.2008 at 02:08AM PST, ID: 23212094
[x]
Attachment Details

Cisco VPN client and allow local LAN access

Asked by diegobalgera in Virtual Private Networking (VPN), IPSec Security Protocol, Cisco PIX Firewall

Hi,

my question is about the "local lan access" using the Cisco VPN client.

When I establish the VPN, all the traffic is injected in the IPSec VPN. Checking the VPN client status (Status / statistics) I see that:
- in "tunnel details", the local LAN is disabled (nothing changes if I enable the "allow local LAN access" in the VPN client profile, as it is overwritten by the VPN gateway administrator)
- in "route details", the whole traffic is secured (no local lan routes and 0.0.0.0/0.0.0.0 in the secured routes)

However, I do need to access some resources locally and changing the configuration of the VPN gateway (allow the local LAN and add local lan routes) is unfortunately not an option :-((

Referring to the VPN client documentation, it states: "this feature (local LAN access) works only on one NIC card, the same NIC card as the tunnel". So I added a second NIC and configured the routing to the local resources via this second NIC but no way: when the VPN is established via the primary card still the access to local resources is prevented. I see that the routing table is correct and - when I initiate the traffic - only the arp entry appears showing that the local resource is being contacted via the second card but no IP traffic is initiated on that path ... :-(

Do you know a possible solution / workaround to access the local resources in this scenario, by using a second NIC card or with whatever else solution?

Thank you in advance!
Best regards.
Diego.
Start Free Trial
[+][-]03.04.2008 at 05:09AM PST, ID: 21040520

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 01:05PM PST, ID: 21045101

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.25.2008 at 10:01AM PDT, ID: 21203774

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.01.2008 at 09:38AM PDT, ID: 21255662

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Virtual Private Networking (VPN), IPSec Security Protocol, Cisco PIX Firewall
Sign Up Now!
Solution Provided By: diegobalgera
Participating Experts: 2
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628