Pix firewall is preventing multiple users behind NAT firewall from VPNing into my network

Posted on 2005-04-05
Last Modified: 2013-11-16
I have two users that are at the same house behind a Linksys Wireless Router (BEFW11S4). The first users connects to our vpn fine. Once the second one goes to connect the first one gets disconnected. The first one (who is now disconnected) also cannot connect to our Outlook Web Access (which is accessible outside our vpn) after their VPN is disconnected.

I'm assuming the router is only allowing 1 connection from that ip address?
Question by:periker
    LVL 13

    Accepted Solution

    The Linksys router uses a VPN passthru method that only allows a single user to have a VPN passthru at the same time.

    I can't find a definitive (linksys) link to show this, but this guys site is usually correct:

    Don't know about the OWA thing, I'd guess it's because the VPN client on the PC is doing something screwy after being disconnected.

    LVL 79

    Expert Comment

    td_miles is correct, the one-at-a-time is a limitation of that router (I have one of those, too, so I speak from experience).
    However, make sure this command is in your PIX:
      isakmp nat-traversal 20

    If the first user gets disconnected by the router, the client may still be holding on to the DNS information given by the VPN connection. What version client are you using? 4.x is the prefered client. If using XP/SP2, then be sure to use the latest 4.05 or 4.6

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
    To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now