Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Setup VPN connection between PIX 506e and Cisco VPN Client

Posted on 2004-09-02
Medium Priority
Last Modified: 2010-04-12

I am trying to establish a VPN connection between PIX 506e and Cisco Client 4.01 I have had little luck with various results.   I ocasionally get connected but when I do the PIX stops responding to internet requests.  Other times I simply cannot get connected.

I used the VPN wizard and assigned a group name and password.  I then setup the same info in the CISCO client.  When I hit connect I usually don't get conencted but rather start dropping packets on the PIX side.   Sometimes I can connect and recieve an IP address from the pool but I can not ping anything.   The pool is on the same subnet as the LAN  192.168.10.xxx   Basically I am looking for help setting this conenction up the proper way.

Question by:draposo
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 36

Expert Comment

ID: 11965952
Hi draposo,
Here are a few links:-
PIX configuration examples - http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_configuration_examples_list.html
PIX configuration basics - http://www.netcraftsmen.net/welcher/papers/pix01.html
PIX ssh configuration - http://www.tech-recipes.com/modules.php?name=Recipes&rx_id=215
My Pages:-
PIX as multi user VPN server - http://www.gbnetwork.co.uk/networking/ciscopixvpnradius.html
PIX as a home DSL firewall - http://www.gbnetwork.co.uk/networking/ciscopixhomedsl.html

Firstly the VPN pool should be on a different subnet than your internal IP range. This is probably the cause of your problems.
Also client 4.01 is fairly old and so I would try and get an updated version.

Author Comment

ID: 11968263
It seems like the actual problem that I am having might have ot do with VPN passthrough.  I can connect to the VPN PIX using the VPN client ( I reset the config) to SITE 1.   It looks like services on SITE 1 are OK but I also need to access services at SITE 2 which is connected via a Site-to-Site VPN tunnel but I can't get through.   Both sites are running PIX software.
I can ping site 1 LAN addresses but I can't ping Site 1 VPN router.  I can not ping anything at site 2.  However, if I am connected only through the site-to-site traffic flows between these without a problem.

LVL 36

Expert Comment

ID: 11971433
Can you clarify where exactly you are connecting from in these two cases.

You can VPN from the internet to SITE1 ok?
When you are connected to SITE1 via VPN you cannot talk to the servers at SITE2?

Is the PIX you connect to at SITE1 also the same PIX used for the site-site VPN?
Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!


Author Comment

ID: 11977014

first of all thanks for your patience in getting responses from me and your help. I think I can clarify the situation a bit better today than yesterday.   Forget about the SITE to SITE VPN .. it makes sense that that does not work because a PIX will not allow you to traverse the same interface in two directions.  So here is the long of it.

I have a user who is going to be connecting to our Network (SITE) via a VPN over a wireless ISP (ISP1).   The user is using the Cisco VPN client and the SITE is a Cisco PIX 506e .  They can establish connectivity and can also connect via the VPN tunnel.  However, once they are connected they cannot do anything local at the SITE.
I found out today that this is only when on ISP1.  When I connect to another ISP (ISP2) and open the exact  same VPN tunnel they can do whatever they want.   It seems to have something to do with Ipsec over NAT .. but when I put a router between the client and ISP2 they can still connect.  So .. is the issue on the ISP side or is there something on the PIX or VPN client that I must enable?   Thanks again for any help you can provide.

LVL 36

Accepted Solution

grblades earned 2000 total points
ID: 11977448
It looks line there is no NAT involved so it wont be that.

I expect that ISP1 is blocking esp (ip protocol number 50) which is the protocol used to carry the encrypted data. If this is blocked you will be able to authenticate as this uses ISAKMP (UDP port 500) but not transfer any data.

Author Comment

ID: 11996439

Thanks for the help.  We are up and running oven the VPN.

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've had to do a bit of research to setup my VPN connection so that Clients can access Windows Server 2008 network shares.  I have a Cisco ASA 5510 firewall.  I found an article which was extremely useful: It had a solution if you use ASDM to config…
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question