wotech
asked on
cisco PIX 501 VPN clients can't ping external net when connected
hi all,
I have a Cisco PIX 501 at an office that users connect to when they're at home. They are all using the Microsoft VPN client/software built-in to Windows XP Pro.
I went through the setup wizard on the PIX 501 to setup client VPN access; everything seemed to go smoothly.
When clients are connected via VPN to the PIX, everyone can access internal network resources (computer, printers, servers, etc.) just fine. However, they can't browse the Internet or do anything externally. After they disconnect the from VPN, Internet works fine again.
When I went through the setup wizard on the PIX, it asked for DNS servers to assign to the clients; I entered the same thing that I assign the computers inside the LAN--
DNS 1: 192.168.1.33 (Win Small Biz Server 2003/domain controller)
DNS 2: 68.13.16.xxx (ISP's DNS server)
If you need more info on the setup, just let me know. any help is appreciated!! Thanks!
I have a Cisco PIX 501 at an office that users connect to when they're at home. They are all using the Microsoft VPN client/software built-in to Windows XP Pro.
I went through the setup wizard on the PIX 501 to setup client VPN access; everything seemed to go smoothly.
When clients are connected via VPN to the PIX, everyone can access internal network resources (computer, printers, servers, etc.) just fine. However, they can't browse the Internet or do anything externally. After they disconnect the from VPN, Internet works fine again.
When I went through the setup wizard on the PIX, it asked for DNS servers to assign to the clients; I entered the same thing that I assign the computers inside the LAN--
DNS 1: 192.168.1.33 (Win Small Biz Server 2003/domain controller)
DNS 2: 68.13.16.xxx (ISP's DNS server)
If you need more info on the setup, just let me know. any help is appreciated!! Thanks!
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
<<theoretically, though, shouldn't I be able to route traffic through the remote gateway?
No - a PIX will not redirect traffic out an interface it originated from. In this case the pptp traffic comes in on the outside interface - and if you wanted to go the internet, it would have to back out the outside interface. The pix will not allow this.
Glad you got working!
No - a PIX will not redirect traffic out an interface it originated from. In this case the pptp traffic comes in on the outside interface - and if you wanted to go the internet, it would have to back out the outside interface. The pix will not allow this.
Glad you got working!
ASKER
ok
cool, thx for the info
have some points!
cool, thx for the info
have some points!
welcome bro
thank you
thank you
ASKER
thanks.
theoretically, though, shouldn't I be able to route traffic through the remote gateway?