Solved

Cisco Conentrator

Posted on 2008-10-15
8
287 Views
Last Modified: 2010-04-12
I have a cisco vpn conentrator 3005. i can connect to via vpn just fine from the cisco client software but i cannot ping any local ips or any server names over the vpn. i do have the split tunneling turned on but cannot figure out why i cannot ping or browse network folders.
0
Comment
Question by:chrisglissman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22723141
Can you check and confirm if the IP subnet of the client is same as the IP subnet of the network behind Cisco device; if yes, this is the problem. You would need to change the IP subnet at one of the ends.

Also, I would like to check if there is a firewall on the local machine which is interrupting with the traffic flow and finally you have allowed traffic on the concentrator to the remote users.

Thank you.
0
 

Author Comment

by:chrisglissman
ID: 22723176
so what you are saying is if my local servers in my office are 10.0.1.1/24 my vpn clients have to be like 10.0.2.1/24????????
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22723343
That is correct; they both cannot be 10.0.1.x/24

Thank you.
0
Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

 

Author Comment

by:chrisglissman
ID: 22723491
how do i  allow traffic on the concentrator to the remote users?
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22723704
Sorry for the confusion; remote user access configuration is done on PIX/ASA not on concentrator.

Have you ensured that the client and network subnets are different.

Thank you.
0
 

Author Comment

by:chrisglissman
ID: 22724162
yes i have set up clients on the vpn3005 to get address 10.0.2.1- 10.0.2.30 i can connect but cannot ping any local 10.0.1.1/24 ips nor can i ping there names.
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22727945
No this is not what I meant when I specified that the remote clients should be on different subnet. Let me clarify:

Let's say a client "A" connects from home; he is having a Linksys router and the network he is on behind linksys is 10.0.1.0/24.
Noe let's say the user wants to create VPN to concentrator; he does that and as the network behind concentrator is also 10.0.1.0/24; he would successfully get connected but there would be no packet flow.

So, you need to change the IP subnet at one of the ends; normally we would change subnet at the Linksys end as it is easy to implement [but if you wish you can also change the IP subnet at concentrator end].
Please revert the virtual IP pool for the remote user on concentrator back to the range you had specified earlier [10.0.1.x]

Thank you.
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 500 total points
ID: 22731597
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question