Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Cisco Conentrator

Posted on 2008-10-15
8
Medium Priority
?
291 Views
Last Modified: 2010-04-12
I have a cisco vpn conentrator 3005. i can connect to via vpn just fine from the cisco client software but i cannot ping any local ips or any server names over the vpn. i do have the split tunneling turned on but cannot figure out why i cannot ping or browse network folders.
0
Comment
Question by:chrisglissman
  • 5
  • 3
8 Comments
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22723141
Can you check and confirm if the IP subnet of the client is same as the IP subnet of the network behind Cisco device; if yes, this is the problem. You would need to change the IP subnet at one of the ends.

Also, I would like to check if there is a firewall on the local machine which is interrupting with the traffic flow and finally you have allowed traffic on the concentrator to the remote users.

Thank you.
0
 

Author Comment

by:chrisglissman
ID: 22723176
so what you are saying is if my local servers in my office are 10.0.1.1/24 my vpn clients have to be like 10.0.2.1/24????????
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22723343
That is correct; they both cannot be 10.0.1.x/24

Thank you.
0
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

 

Author Comment

by:chrisglissman
ID: 22723491
how do i  allow traffic on the concentrator to the remote users?
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22723704
Sorry for the confusion; remote user access configuration is done on PIX/ASA not on concentrator.

Have you ensured that the client and network subnets are different.

Thank you.
0
 

Author Comment

by:chrisglissman
ID: 22724162
yes i have set up clients on the vpn3005 to get address 10.0.2.1- 10.0.2.30 i can connect but cannot ping any local 10.0.1.1/24 ips nor can i ping there names.
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22727945
No this is not what I meant when I specified that the remote clients should be on different subnet. Let me clarify:

Let's say a client "A" connects from home; he is having a Linksys router and the network he is on behind linksys is 10.0.1.0/24.
Noe let's say the user wants to create VPN to concentrator; he does that and as the network behind concentrator is also 10.0.1.0/24; he would successfully get connected but there would be no packet flow.

So, you need to change the IP subnet at one of the ends; normally we would change subnet at the Linksys end as it is easy to implement [but if you wish you can also change the IP subnet at concentrator end].
Please revert the virtual IP pool for the remote user on concentrator back to the range you had specified earlier [10.0.1.x]

Thank you.
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 1500 total points
ID: 22731597
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Using Windows 2008 RRAS, I was able to successfully VPN into the network, but I was having problems restricting my test user from accessing certain things on the network.  I used Google in order to try to find out how to stop people from accessing c…
OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question