Solved

AT&T VPN client does not work in a LAN however other VPN clients works in this same LAN

Posted on 2007-04-10
13
803 Views
Last Modified: 2012-06-21
My network has Cisco Pix between LAN and the ISP.  Inside the LAN, users are able to use various VPN clients (Cisco, CheckPoint, Nokia) to connect to other companies.  A new VPN client is required to be used and it is an AT&T VPN client.  This AT&T VPN client does not work in this same environment.  Are there any special PIX config to be done to allow this AT&T VPN client?
0
Comment
Question by:royrubio
  • 7
  • 4
  • 2
13 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 300 total points
Comment Utility
Have you enabled nat-traversal on your pix?

 isakmp nat-traversal 20

Do you support your own VPN tunnels/clients on the pix? If not you can enable esp-ike fixup.
0
 
LVL 22

Assisted Solution

by:WMIF
WMIF earned 200 total points
Comment Utility
do you know anything about the AT&T client?  does it use GRE tunnels?
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Good thought, WMIF..
Try adding this to the PIX config:
  fixup protocol pptp 1723
0
 

Author Comment

by:royrubio
Comment Utility
Nat-traversal did not solve the problem.  I do not know anything about the AT&T client.  I will add the fixup and test.
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 300 total points
Comment Utility
If you have extra public IP addresses, you can try a 1-to-1 static public ip to this client..
0
 
LVL 22

Assisted Solution

by:WMIF
WMIF earned 200 total points
Comment Utility
what version of the client is your user running?
http://support.microsoft.com/kb/925479
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 

Author Comment

by:royrubio
Comment Utility
Adding fixup to the PIX did not do any good.

The AT&T VPN client runs alright on the same PC if I route it through a Cisco IOS firewall.  We don't have issues with the PC and AT&T VPN client configuration.  It is the Cisco PIX that is not allowing it.

 
0
 

Author Comment

by:royrubio
Comment Utility
I need a solution for Cisco PIX because I have a site which uses PIX only.
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 300 total points
Comment Utility
did you try a 1-1 static nat for this inside host?
static (inside,outside) <public ip> <host ip> netmask 255.255.255.255

You should not need any access list entries, but you could try adding
access-list <outside_in> permit ip host <at&t vpn endpoint> host <public ip>
0
 

Author Comment

by:royrubio
Comment Utility
Lrmore, have not tried it yet.  Will try next week.
0
 

Author Comment

by:royrubio
Comment Utility
Sorry, I don't have spare public IP to test.  Any more ideas other than this?
0
 

Author Comment

by:royrubio
Comment Utility
Any more ideas please?
0
 

Author Comment

by:royrubio
Comment Utility
This remains an open problem for me but I managed to route traffic to an IOS firewall instead of the Pix.  I'm closing this query for now.  I'm splitting points to those who tried to help:  300 for lrmoore and 200 for wmif.  Thanks for your help.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now