Cisco PIX 506e + Cisco VPN Client 4.03 -- Connectivity Problems

I have about 10 clients (including myself) - all Windows XP SP2 - all are using Cisco's VPN Client v. 4.0.3(c) All of them are coming from behind the same firewall/router.  

From time to time we can not access the VPN if one of us is already connected. And if someone then disconnects it takes a while to get back in. The errors are that the client can not communicate with the gateway, or the gateway does not exist.

The VPN config looks something like this:

access-list no_nat permit ip 192.168.1.0 255.255.255.0 10.0.1.0 255.255.255.0
access-list split_tunnel permit ip 192.168.1.0 255.255.255.0 10.0.1.0 255.255.255.0
ip local pool ip-pool 10.0.1.1-10.0.1.254
crypto ipsec transform-set trmset1 esp-aes-256 esp-sha-hmac
crypto dynamic-map dynmap 10 set transform-set trmset1
crypto map vpnmap 10 ipsec-isakmp dynamic dynmap
isakmp key ******** address 0.0.0.0 netmask 0.0.0.0
isakmp identity address
isakmp nat-traversal 20
isakmp policy 2 authentication pre-share
isakmp policy 2 encryption aes-256
isakmp policy 2 hash sha
isakmp policy 2 group 1
isakmp policy 2 lifetime 86400
vpngroup groupvpn address-pool ip-pool
vpngroup groupvpn dns-server 192.168.1.20
vpngroup groupvpn split-tunnel split_tunnel
vpngroup groupvpn idle-time 1800
vpngroup groupvpn user-idle-timeout 1800
vpngroup groupvpn password ********

Any ideas?
LVL 2
just1coderAsked:
Who is Participating?
 
lrmooreCommented:
>all Windows XP SP2 - all are using Cisco's VPN Client v. 4.0.3(c)
This client is not compatible with XP SP2
You will need 4.05 or 4.6

0
 
lrmooreCommented:
All the clients are behind this PIX?
Are you all connecting to the same remote site?
0
 
just1coderAuthor Commented:
-I'll try the new client - available at Cisco?
-Clients are not behind the PIX - VPN...behind a Linksys
-All connecting to the same remote site.
0
On-Demand: Securing Your Wi-Fi for Summer Travel

Traveling this summer?Check out our on-demand webinar to learn about the importance of Wi-Fi security and 3 easy measures you can start taking immediately to protect your private data while using public Wi-Fi. Follow us today to learn more!

 
lrmooreCommented:
>Clients are not behind the PIX - VPN...behind a Linksys
What model Linksys? That's the weak link in its inability to create multiple tunnels at the same time.
Any wireless?
I'm using Linksys WRV54G router with permanent lan-lan VPN tunnel to PIX at office...
Works a treat!
RV042/82 and BEFV41 also work well with PIX..
0
 
just1coderAuthor Commented:
-Linksys BEFSR41 - latest BIOS
-No wireless,...
-I also have a PIX-PIX VPN that has not given ANY trouble ever...

Where can I track down the latest VPN client? Is it only available from Cisco?
0
 
lrmooreCommented:
Only available from Cisco..
http://www.cisco.com/kobayashi/sw-center/vpn/client/

I would suggest upgrading the Linksys, then you don't have to worry about any of the PC's needing the client.
It will only support one connection at a time, and then you may have to wait for the SA to timeout before you can make another connection. Even those linksys routers that purport to support multiple simultaneous VPN connections only mean multiple connections to different endpoints, not to the same. A lan-lan VPN would definately be better for you.
0
 
just1coderAuthor Commented:
aaaah .... I was wondering about that as I have >2 boxes at home running the same client version as well as XP SP2 and they have no trouble.

I will have to try out the client upgrades first as they will be the easiest to test at 6PM on a Friday :)
0
 
lrmooreCommented:
Any progress? Are you still working on this? Do you need more information?
0
 
just1coderAuthor Commented:
Distributing 4.6 now ... will advise...

I have a Netgear WGR614 v4 ... would that be a suitable replacement for the aged Linksys?
0
 
lrmooreCommented:
That's one I have no experience with, but it appears to be a decent product. I've never been a fan of Netgear, but since Nortel bought them, I guess that helps..
Nortel likes to take a different track,especially when it comes to interopating with Cisco products, though.
Linksys is owned by Cisco, and you have a Cisco PIX as the end point. 'nuff said...
0
 
just1coderAuthor Commented:
;) The new clients seems to be helping out.. thanks again!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.