?
Solved

How Do I setup a VPN on a 506/e

Posted on 2005-04-05
2
Medium Priority
?
179 Views
Last Modified: 2013-11-16
Hi

 I am trying to set up a vpn with a pix 506/e. I am not completely dumb when it comes to cisco equipment but I am unable to get this to work. I am using the vpn wizard. When I try to connect the password requester comes up and accepts the user name and password then nothing happens. With the Cisco client I see it saying ( If I remember correctly) something about establishing a secrure channel and eventually just times out. Help. What would be the simple straight forward steps using the wizard to setup a vpn
0
Comment
Question by:itspecearthlink
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 1000 total points
ID: 13711459
If you can post your config, I can probably help you out..
Stepping through the Wizard:
  Select type: Remote AccessVPN
   Select interface: outside
Next
 * Cisco VPN client
Next
  Group Name:  MYVPNGROUP
  * Pre shared key
      mygrouppassword
      mygrouppassword
Next
  Enable Extended Client Authentication  <== uncheck this box
  nothing is checked on this page
Next
 Pool name:  MYVPNPOOL
  Range start:  192.168.22.1
           end:     192.168.22.22
Next
  Fill in your local primary DNS server, WINS server and default domain name
Next
 Select:  3DES |  MD5  | Group2(1024bit)
Next
 3DES  | MD5
Next
  Host/Network
  *ip address
    Interface inside
    ip address 192.168.1.0  <== whatever is your local LAN
    mask: 255.255.255.0
 Add >>
  X Enable split tunneling
Finish

When you setup the client:
New Entry
  Connection:  <whatever>
  Descript:  <whatever>
  Host:  OUTSIDE IP of PIX
Authentication
  * Group auth
       Name: MYVPNGROUP
       Pass:  mygrouppassword
       Confirm: mygrouppassword
Transport Tab
  X Enable Transparent Tunneling
     * IpSec over UDP (NAT/PAT)
Save
Connect

You should not see another username/password prompt again. It should just connect staight away.
You may have to enable NAT Traversal.
From the Main GUI window, VPN tab
  IKE
     Policies
        Right about the center of the window there is a chekbox
                                     [X] Enable NAT traversal
       Apply
        Save

Done


0
 

Author Comment

by:itspecearthlink
ID: 13731424
Hi lrmoore

Thank you, you definetly have me on the right track. However, setting it up with your config it worked fine until I change something and then nothing will work. I have to completely reset the 506/E and then run the VPN wizard again using your config and it will connect. I tried changing the IP address pool to mine with your config and then it won't work. If I try to go back to your pool it still won't work. I again have to completely reset the 506/E and then run the wizard again. It seems like if I change anything I then have to go back and reset the Pix and start over.
0

Featured Post

2018 Annual Membership Survey

Here at Experts Exchange, we strive to give members the best experience. Help us improve the site by taking this survey today! (Bonus: Be entered to win a great tech prize for participating!)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
This video tutorial shows you the steps to go through to set up what I believe to be the best email app on the android platform to read Exchange mail.  Get the app on your phone: The first step is to make sure you have the Samsung Email app on your …
Suggested Courses

601 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question