Cisco Conentrator

I have a cisco vpn conentrator 3005. i can connect to via vpn just fine from the cisco client software but i cannot ping any local ips or any server names over the vpn. i do have the split tunneling turned on but cannot figure out why i cannot ping or browse network folders.
chrisglissmanAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

dpk_walCommented:
Can you check and confirm if the IP subnet of the client is same as the IP subnet of the network behind Cisco device; if yes, this is the problem. You would need to change the IP subnet at one of the ends.

Also, I would like to check if there is a firewall on the local machine which is interrupting with the traffic flow and finally you have allowed traffic on the concentrator to the remote users.

Thank you.
0
chrisglissmanAuthor Commented:
so what you are saying is if my local servers in my office are 10.0.1.1/24 my vpn clients have to be like 10.0.2.1/24????????
0
dpk_walCommented:
That is correct; they both cannot be 10.0.1.x/24

Thank you.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

chrisglissmanAuthor Commented:
how do i  allow traffic on the concentrator to the remote users?
0
dpk_walCommented:
Sorry for the confusion; remote user access configuration is done on PIX/ASA not on concentrator.

Have you ensured that the client and network subnets are different.

Thank you.
0
chrisglissmanAuthor Commented:
yes i have set up clients on the vpn3005 to get address 10.0.2.1- 10.0.2.30 i can connect but cannot ping any local 10.0.1.1/24 ips nor can i ping there names.
0
dpk_walCommented:
No this is not what I meant when I specified that the remote clients should be on different subnet. Let me clarify:

Let's say a client "A" connects from home; he is having a Linksys router and the network he is on behind linksys is 10.0.1.0/24.
Noe let's say the user wants to create VPN to concentrator; he does that and as the network behind concentrator is also 10.0.1.0/24; he would successfully get connected but there would be no packet flow.

So, you need to change the IP subnet at one of the ends; normally we would change subnet at the Linksys end as it is easy to implement [but if you wish you can also change the IP subnet at concentrator end].
Please revert the virtual IP pool for the remote user on concentrator back to the range you had specified earlier [10.0.1.x]

Thank you.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
VPN

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.