Link to home
Start Free TrialLog in
Avatar of briandaniel
briandaniel

asked on

VPN 3000 Concentrator multiple connections from one site.

We have a Cisco VPN 3000 Concentrator and can't find a way to allow more than one computer at a time from an offsite location to connect. Example -offsite office has 4 computers connected to DSL and only one at a time can connect to the VPN concentrator. Is there a setting that will allow multiple connections.
Avatar of amoldkelkar
amoldkelkar

Hi,
Is there any router or a firewall sitting at the remote site? It might be doing PAT
Also can you check on the version of your concentrator or client software version?
Also make sure you have enabled NAT-T thats NAT traversal as well?
Let me know if anything helps.

-AK
Is there any IP Pool used on the concentrator? Is so the check if the range doesnt overlap with any of the existing ips in network.
You may even want to refer/follow the concentrator config as well,
http://www.cisco.com/warp/public/471/ipsec_3000.pdf

-AK
Avatar of briandaniel

ASKER

The following information is what shows for the versions. It does have NAT-T enabled.

VPN Concentrator Type: 3005
Bootcode Rev: Cisco Systems, Inc./VPN 3000 Concentrator Series Version 2.5.Rel Jun 21 2000 18:57:52
Software Rev: Cisco Systems, Inc./VPN 3000 Concentrator Version 4.1.7.E Mar 14 2005 13:41:22
IS there anyway you group all the remote users?

Can you please post your network diagram as well as the config if possible?

-AK
HI,
Sorry for too many clarifications but even i am trying to figure out the problem and understand.

Are you using Cisco ACS on windows machine for remote users? If so then you might want to check if you have added all users under the group.
You may refer to the following link for the steps,
http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a00807f6e76.shtml#backinfo

-AK
R the 4 offsite comps creating dial-up VPNs with the concentrator?
R they on same LAN? I think so. Correct me if i am wrong.

If thats the case and if you have a firewall set on the remote LAN side then i would suggest you to go for site-to-site than dialup vpns
using site to site you will be able to have access for any number of users.

-AK
Also if they r 4 dial-up vpns using the same outgoing gateway then its working at it should work.
Only 1 user can work at a time.
Reason because they are on same LAN and using same outgoing gateway.

So i suggested you can have site-to-site if possible.

-AK
The last comment about the same outgoing gateway must be the problem because they are using the same gateway. I don't have a diagram of the network, it is a complete mess and I have only been here a short time. I am in the process of trying to straighten things out, but keep running into different problems. I haven't had to setup a site to site, do you know of any good documentation? Thanks!
ASKER CERTIFIED SOLUTION
Avatar of amoldkelkar
amoldkelkar

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial