troubleshooting Question

Cisco PIX Remote Access VPN

Avatar of plexter2k
plexter2kFlag for Canada asked on
VPNInternet Protocol SecurityCisco
25 Comments1 Solution360 ViewsLast Modified:
Hello,

I have been trying to get my remote access VPN enabled but for some reason I am unable to access my internal LAN.

My network has two firewalls. The PIX and an internal proxy server/firewall dealy.

Network (relevant) is something like this:

[internet] -- [pix fw] -- [proxy] -- [Internal lan]

Things that DO work:

-I can connect and authenticate to the VPN
-I can PING the EXTERNAL IP of the PROXY
-I can access the management page for the PROXY

Things I CANT do; but need to:

-Access any host behind the proxy (internal LAN)
-Use split-tunnel to be able to access the internet and use the VPN at the same time; would prefer to use the DNS servers located on the LAN


I've attached my configuration hoping someone can take a look to see what is wrong (if anything).

I do not see any logs (deny traffic) on the proxy when trying to access the internal host. This tells me the problem is on the PIX I presume.

IP Addressing...

PIX internal IP - 192.168.254.1
Proxy External IP - 192.168.254.2
Proxy Internal IP - 10.10.254.1
Internal LAN - 10.10.254.2...etc
VPN Pool is - 10.10.254.32 /29

Hope you can help; need any more info please let me know!

Thanks
config.txt
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 25 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 25 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros