Solved

Setup VPN connection between PIX 506e and Cisco VPN Client

Posted on 2004-09-02
6
899 Views
Last Modified: 2010-04-12
Hi,

I am trying to establish a VPN connection between PIX 506e and Cisco Client 4.01 I have had little luck with various results.   I ocasionally get connected but when I do the PIX stops responding to internet requests.  Other times I simply cannot get connected.

I used the VPN wizard and assigned a group name and password.  I then setup the same info in the CISCO client.  When I hit connect I usually don't get conencted but rather start dropping packets on the PIX side.   Sometimes I can connect and recieve an IP address from the pool but I can not ping anything.   The pool is on the same subnet as the LAN  192.168.10.xxx   Basically I am looking for help setting this conenction up the proper way.

Thanks
0
Comment
Question by:draposo
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 36

Expert Comment

by:grblades
ID: 11965952
Hi draposo,
Here are a few links:-
PIX configuration examples - http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_configuration_examples_list.html
PIX configuration basics - http://www.netcraftsmen.net/welcher/papers/pix01.html
PIX ssh configuration - http://www.tech-recipes.com/modules.php?name=Recipes&rx_id=215
My Pages:-
PIX as multi user VPN server - http://www.gbnetwork.co.uk/networking/ciscopixvpnradius.html
PIX as a home DSL firewall - http://www.gbnetwork.co.uk/networking/ciscopixhomedsl.html

Firstly the VPN pool should be on a different subnet than your internal IP range. This is probably the cause of your problems.
Also client 4.01 is fairly old and so I would try and get an updated version.
0
 

Author Comment

by:draposo
ID: 11968263
Hi,
It seems like the actual problem that I am having might have ot do with VPN passthrough.  I can connect to the VPN PIX using the VPN client ( I reset the config) to SITE 1.   It looks like services on SITE 1 are OK but I also need to access services at SITE 2 which is connected via a Site-to-Site VPN tunnel but I can't get through.   Both sites are running PIX software.
I can ping site 1 LAN addresses but I can't ping Site 1 VPN router.  I can not ping anything at site 2.  However, if I am connected only through the site-to-site traffic flows between these without a problem.

THANKS
0
 
LVL 36

Expert Comment

by:grblades
ID: 11971433
Can you clarify where exactly you are connecting from in these two cases.

You can VPN from the internet to SITE1 ok?
When you are connected to SITE1 via VPN you cannot talk to the servers at SITE2?

Is the PIX you connect to at SITE1 also the same PIX used for the site-site VPN?
0
Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

 

Author Comment

by:draposo
ID: 11977014
grblades,

first of all thanks for your patience in getting responses from me and your help. I think I can clarify the situation a bit better today than yesterday.   Forget about the SITE to SITE VPN .. it makes sense that that does not work because a PIX will not allow you to traverse the same interface in two directions.  So here is the long of it.

I have a user who is going to be connecting to our Network (SITE) via a VPN over a wireless ISP (ISP1).   The user is using the Cisco VPN client and the SITE is a Cisco PIX 506e .  They can establish connectivity and can also connect via the VPN tunnel.  However, once they are connected they cannot do anything local at the SITE.
   
I found out today that this is only when on ISP1.  When I connect to another ISP (ISP2) and open the exact  same VPN tunnel they can do whatever they want.   It seems to have something to do with Ipsec over NAT .. but when I put a router between the client and ISP2 they can still connect.  So .. is the issue on the ISP side or is there something on the PIX or VPN client that I must enable?   Thanks again for any help you can provide.

0
 
LVL 36

Accepted Solution

by:
grblades earned 500 total points
ID: 11977448
It looks line there is no NAT involved so it wont be that.

I expect that ISP1 is blocking esp (ip protocol number 50) which is the protocol used to carry the encrypted data. If this is blocked you will be able to authenticate as this uses ISAKMP (UDP port 500) but not transfer any data.
0
 

Author Comment

by:draposo
ID: 11996439
grblades.


Thanks for the help.  We are up and running oven the VPN.
0

Featured Post

Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have an old router lying around the house that you don’t know what to do with? Check the make and model, then refer to either of these links to see if its compatible. http://www.dd-wrt.com/site/support/router-database http://www.dd-wrt.c…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question