We help IT Professionals succeed at work.

Check out our new AWS podcast with Certified Expert, Phil Phillips! Listen to "How to Execute a Seamless AWS Migration" on EE or on your favorite podcast platform. Listen Now

x

Cisco PIX VPN not passing traffic

Medium Priority
385 Views
Last Modified: 2013-11-16
I have a client VPN setup in a PIX firewall. The VPN connects fine, but it will not pass traffic to the inside network. The config is exactly like the config on Cisco's site, but it will not pass traffic. I am using PIX 6.3(3) and the VPN client is 4.2

Thanks,

Sean
Comment
Watch Question

Commented:
can you ping the inside from the pix ??

Author

Commented:
Yes, the connectivity from the PIX to the inside is fine. The PIX is passing traffic fine. Once I connect with the VPN, I can't ping to the inside interface or beyond from the client
Les MooreSr. Systems Engineer
CERTIFIED EXPERT
Top Expert 2008

Commented:
Do your clients get an IP address in a range that is different from your inside LAN?
You'll never be able to ping the inside interface from the VPN...
Is the PIX's inside interface the default gateway for any other systems that you are trying to access?

Commented:
I'm assuming that your client machine is running Windows.  Check on the client machine that you're not sharing any internet connections.  If internet connection sharing is enabled, then the client will connect, but not pass any traffic.

Jon
MAke sure you peers are set correctly. if you have a edge router and a firewalll behind the edge router sometimes you will need to use the outside interface of the pix not the edge router as that is where your crypto statments are set.

Author

Commented:
I actually have solved this problem on my own, but I am not sure how to close out the question with zero points.  THe solution was to enable NAT Traversal and split-tunneling.
Just give the points to those that were helping. Their ideas may have been all you needed to resolve the issue.  
TolomirAdministrator
CERTIFIED EXPERT
Top Expert 2005

Commented:
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:
PAQ - Refund points

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

Tolomir
EE Cleanup Volunteer
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a free trial preview!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.