Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Cannot access a network using cisco vpn client from behind a firewall, connection ok, but no access to content on network

Posted on 2008-10-22
11
Medium Priority
?
723 Views
Last Modified: 2012-06-27
I am having trouble connecting to a cisco vpn using client version 5.0.01.0600 from behind a firewall. The connection appears to connect and i am assigned an ip address, but i cannot browse to any ip addresses behind the firewall.

I am running vista on a pc in a SBS 2000 environment using the inbuilt software firewall and a binatone router.

I have opened ports 500 and 4500 on the router and the firewall as i read these were the ports the VPN client uses for traffic, but still no joy.

Any help or advice gratefully appreciated!
0
Comment
Question by:simplethinking
  • 4
  • 4
  • 2
  • +1
11 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 22775106
Hello simplethinking,

add the following linne to the config on the cisco firewall

crypto isakmp nat-traversal  20



Regards,

PeteLong
0
 

Author Comment

by:simplethinking
ID: 22775124
Thanks for the speedy response pete.

Unfortunately we do not have direct access to the firewall.

Is there anything we can do here to enable the connection??
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22776345
I'm guessing the problem is NAT, short of moving outside of the firewall, theres not a lot you can do
0
Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

 
LVL 16

Expert Comment

by:btassure
ID: 22780369
You could try going into the connection profile properties, then the transport tab and changing the tunneling to ipsec over tcp but I doubt it will work properly. PeteLong is correct that any changes to get it working will likely need to be done on the firewall. Have you got correct DNS servers etc?
0
 

Author Comment

by:simplethinking
ID: 22784755
Good morning,

I have done further testing.  The Cisco vpn software connects correctly, once the connection has been established I have tried:
- Pinging the ip address we are tring to reach and get an immediate time out response
- Tracert and this doesnt return anything and eventually times out

This would indicate the problem is an issue with all external IP requests being blocked by our firewall when the Cisco VPN software is active.

Thank you for time and patience,



0
 
LVL 16

Expert Comment

by:btassure
ID: 22787756
If it is connected then it is almost certainly a configuration issue either on the servers at the VPN host end or the VPN head end firewall. The local firewall won't block the pings as they are encapsulated into the IPSEC traffic destined for the firewall. The local firewalls will only see encrypted IPSEC packets, not the pings.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22790347
If a tunnle connect and no traffic passes 99% of the time the problem is NAT - either the Nat 0 command is missing on the Cisco, there is no ACL that matched that NAT 0 command or Nat-traversal has not been enabled
0
 

Author Comment

by:simplethinking
ID: 22830370
Hi PeteLong,

Thank you for answers.

 I can successfully connect and browse website on the VPN from my standard home internet ADSL internet connection.  Is the problem being caused by our firewall vs the home connection?
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 1500 total points
ID: 22832682
If you can connect and browse what is the problem m8?
0
 

Author Comment

by:simplethinking
ID: 22832773
Hi PeteLong,

As per the orginal post we can connect the vpn from inside our company network (on my laptop) however when we try to browse website hosted inside that network we get blocked at somepoint.

"The Cisco vpn software connects correctly, once the connection has been established I have tried:
- Pinging the ip address we are tring to reach and get an immediate time out response
- Tracert and this doesnt return anything and eventually times out"

If i connect to the vpn from home (on the same laptop) the vpn connects fine and I can browse the internal website without any problems.

The issue is we need the vpn and browsing to work from inside our network.
0
 
LVL 4

Expert Comment

by:Tachyon_1
ID: 25761120
I'm not sure why you would run the VPN when you are inside the network, but anyway...

Have you tried enabling the "Allow local LAN access" option from the Transport tab of the VPN client "modify configuration" menu?
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month10 days, 11 hours left to enroll

886 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question