Cisco ASA IPSEC VPN Troubleshooting

Posted on 2014-07-20
Last Modified: 2014-08-09
Hello all..I've set up 100 of these before but I cannot figure this out for the life of me.

I can get VPN client to connect fine. I cannot ping through the VPN from the outside VPN client.

I can however, ping from inside the network to the VPN client on the other end.

Here's the config

: Saved
ASA Version 8.3(1)
enable password password di7P1TO level 0 encrypted
enable password gM7M1 e level 1 encrypted
enable password di7P1TObTEsgM7M1 encrypted
passwd dTlFQE/VXBER7Fmp encrypted
name UPSDC
name ABYSS
name UPSDC2
name LynnR
name HeatherM
name KimT
name designasst
name JoDDesign
name GraphicsMac2
name GraphicsMac1
name Gateway
name BobWilson
name TheresaM
name CPugh
name KJones
name KevinP
name RickS
name RobinB
name Valerie
name designoffice
name NormaT
name SewMgr
name Maintenance
name UPSUP
name ITAndrewOffice
name LisaBramesWired
name LisaBramesWireless
name April
name GaryW
name Phyllis
name Missy
name Karen
name EmilyW
name Travel1laptop
name LewBLaptop
name LewB
name ABBIE
name PitneyBowes
name Jenni
name LynnLaptopWired
name LynnLaptopWireless
name StephanieR
name MicahW
name Purchase
name Sujei
name UPSDCWired
name Webpass
name AbonserLaptop
name AbonserLaptopWireless
name WebServerNIC2
name Webpass2
name BobCorpLaptopWireless
name BobCorpLaptopWired
name Travel1Wireless
name Pass6
name Pass5
name Pass4
name Pass3
name GraphicsIMAC
name GX270CSR
name CarouselPC
name Kitte
name Smartcut
name WebPassDC
name CService
name LectraWeb
name Tony
name Tpounds
name UPSDC2wired
name EmbGraphics
name HQCafeKiosk
name ExchangeDefender2
name ExchangeDefender1
name ExchangeDefender3
name ExchangeDefender9
name ExchangeDefender7
name ExchangeDefender5
name ExchangeDefender6
name ExchangeDefender8
name ExchangeDefender4
name ExchangeDefender10
name MWHQDC1
name MWMailSRV2
name MWMailSRV1
name OptitexPC2
name OptitexPC1
name SewingOffice
name LauraS
name Lectra3
name TOMW
name Pass2
name Radiant
name rods_home
name rod_server_farm
interface Vlan1
 nameif inside
 security-level 100
 ip address
interface Vlan2
 nameif outside
 security-level 0
interface Vlan12
 description guest wireless
 no forward interface Vlan1
 nameif guest
 security-level 50
 ip address
interface Ethernet0/0
 switchport access vlan 2
interface Ethernet0/1
interface Ethernet0/2
interface Ethernet0/3
interface Ethernet0/4
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7
 switchport access vlan 12
time-range WeekdayInternet
 periodic weekdays 5:00 to 18:00
ftp mode passive
clock timezone EST -5
clock summer-time EDT recurring
object network DC_LAN
object network inside_LAN
object network Public_RDP
 host XXXXX71
object network Private_RDP
object network Public_MAIL
 host XXXXX68
object network Private_MAIL
object network Public_WEB_Server
 host XXXXX80
object network Private_WEB_Server
object network Public_VPN
 host XXXXX69
object network Private_VPN

object network AliciaDesktop
 description AliciaDesktop  
object network ITAndrewOffice
 description ITAndrewOffice  
object network MWNEWVIEWS
 description MWNEWVIEWS  
object network MWWEBDEV
 description MWWEBDEV  
object network LectraWestCut
 description Lectra West Cutter  
object network LectraEastCut
 description Lectra East Cutter  
object network GraphicsIMAC2
 description GraphicsIMAC2  
object network AlysPlot
 description Lectra Alys Plotter Workstation  
object network GraphicsDes2
 description Graphics Design Workstation  
object network SwannDVR
 description SwannDVR  
object network JasonWalterPC
object network Pip01
 description Pip01  
object network NewWestCut
 description NewWestCut  
object network AndrewMPhone
 description AndrewM Galaxy Phone  
object network TMasonNetBookWireless
 description TMasonNetBookWireless  
object network AndrewMGalaxyDC
 description AndrewM Galaxy Smartphone DC  
object network CSMworkstation
 description CSM-Pip08 workstation  
object network DCScreenprint
 description DC Screenprint Workstation  
object network mwworkstation04
 description mwworkstation04  
object network mwworkstation03
 description mwworkstation03  
object network pickcarousel
 description pickcarousel workstation  
object network saleslaptop01
 description saleslaptop01  
object network ACCTGSTATION01
 description Accounting Workstation 01  
object network saleslaptop01wireless
 description saleslaptop01wireless  
object network mwworkstation05
 description mwworkstation05  
object network MWBACKUP
 description MWBACKUP  
object network UbuntuServer
 description UbuntuServer  
object network EMBPRODUCTION01
 description EMBPRODUCTION01  
object network acctgstation02
 description acctgstation02  
object network HRDesktop01
 description HRDesktop01  
object network TurkeyLinuxJoomla
 description Turnkey Linux Joomla Host  
object network Abacus
 description Abacus  
object network AccountingServer
 description AccountingServer  
object network ITAndrewPC
 description ITAndrewPC  
object network designstation02
 description designstation02  
object network PCDBSVR
 description PSDBSVR  
object network workstation01
 description workstation01  
object network mwpcdesk01
 description mwpcdesk01  
object network CheerPIP02
 description CheerPIP02  
object network TurnkeyLinuxCollabtiveTest
 description Turnkey Linux Collabtive Test  
object network mwdesktop02
 description MWDESKTOP02  
object network PattExecPC
 description PattExecPC  
object network judyh
object network jodigym
 description jodigym  
object network micahw
 description micahw  
object network Maintenance
 description Maintenance Room PC  
object network MWLAPTOP2-wired
 description MWLAPTOP2-wired  
object network MWLAPTOP2-wireless
 description MWLAPTOP2-wireless  
object network ACCTGSTATION03
 description Acctgstation03  
object network ScaleNode1
 description ScaleNode1  
object network ScaleNode2
 description ScaleNode2  
object network ScaleNode3
 description ScaleNode3  
object network ScaleNode4
 description ScaleNode4  
object network MWSQLSvr
 description SQL 2012 Server  
object network V2KAppSvr
 description V2KAppSvr  
object network Public_V2Kappsvr_RDP
 host XXXXX75
 description Public_V2Kappsvr_RDP  
object network Public_MWSQLSvr_RDP
 host XXXXX85
 description Public_MWSQLSvr_RDP  
object network Private_MWSQLSvr_RDP
 description Private_MWSQLSvr_RDP  
object network Private_V2Kappsvr_RDP
 description Private_V2Kappsvr_RDP  
object network TrainingPC1
 description TrainingPC1  
object network TrainingPC2
 description TrainingPC2  
object network TrainingPC3
 description TrainingPC3  
object network TrainingPC4
 description TrainingPC4  
object network Redbox1
 description Redbox1  
object network Purchase
 description Purchase workstation  
object network redbox2
 description redbox2  
object network PurchasingWS
 description Purchasing Workstation  
object network mwwkstn1
 description mwwkstn1  
object network MWCSRWKSTN1
 description MWCSRWKSTN1  
object network MWWKSTN02
 description MWWKSTN02  
object network NEWDCUPS
 description NEWDCUPS  
object network mwm7laptop1wireless
 description mww7laptop1 wireless  
object network mwm7laptop2wired
 description mww7laptop2 wired  
object network mww7laptop1wired
 description mww7laptop1 wired  
object network mww7laptop2wireless
 description mww7laptop1 wireless  
object network MWSPICEWORKS
 description MWSPICEWORKS VM  
object network USERPC
 description IT Contractor  
object network NETWORK_OBJ_172.16.1.0_24
object network NETWORK_OBJ_172.16.1.13
object network VisualVPNPool
 description Visual2000 VPN POOL  
object network MXLOGIC1
 description AT&T SEG Subnet  
object network MXLOGIC2
 description AT&T SEG  
object network NETWORK_OBJ_10.16.17.0_24
object-group service pptptcp tcp
 port-object eq pptp
object-group service Mail tcp
 description Email
 port-object eq smtp
object-group service httppop tcp
 port-object eq pop3
 port-object eq www
object-group network Servers
 network-object ACCOUNTING
 network-object ABACUS
 network-object ABYSS
 network-object ABBIE
 network-object BACKUP
 network-object DCDBSERVER
 network-object MWHQDC1
 network-object MWHQTS
 network-object MWMailSRV1
 network-object MWMailSRV2
 network-object WebServerNIC2
 network-object object MWNEWVIEWS
 network-object object MWWEBDEV
 network-object object MWBACKUP
 network-object object UbuntuServer
 network-object object Abacus
 network-object object AccountingServer
 network-object object ScaleNode1
 network-object object ScaleNode2
 network-object object ScaleNode3
 network-object object ScaleNode4
 network-object object MWSQLSvr
 network-object object V2KAppSvr
object-group network Executive
 network-object BobWilson
 network-object SewMgr
 network-object NormaT
 network-object PATTEXEC
 network-object designoffice
 network-object Valerie
 network-object RobinB
 network-object RickS
 network-object KevinP
 network-object KJones
 network-object ABONSERDESK
 network-object CPugh
 network-object TheresaM
 network-object Tony
 network-object TOMW
 network-object object TMasonNetBookWireless
 network-object object mwworkstation04
 network-object object HRDesktop01
 network-object object mwwkstn1
object-group network Accounting
 network-object Phyllis
 network-object GaryW
 network-object April
 network-object Jenni
 network-object object ACCTGSTATION01
 network-object object acctgstation02
 network-object object PurchasingWS
object-group network CustomerService
 network-object HeatherM
 network-object LynnR
 network-object EmilyW
 network-object Karen
 network-object GINADESKTOP
 network-object Missy
 network-object Sujei
 network-object GX270CSR
 network-object CService
 network-object Tpounds
 network-object HQKIOSK
 network-object VIDEOPC
 network-object object CSMworkstation
 network-object object mwworkstation05
 network-object object mwpcdesk01
 network-object object mwdesktop02
 network-object object Purchase
 network-object object MWCSRWKSTN1
 network-object object MWWKSTN02
object-group network Design
 network-object GraphicsMac1
 network-object GraphicsMac2
 network-object JoDDesign
 network-object designasst
 network-object KimT
 network-object DESIGNUSER
 network-object MINIDESIGN
 network-object StephanieR
 network-object GraphicsIMAC
 network-object EmbGraphics
 network-object object AliciaDesktop
 network-object host OptitexPC1
 network-object host OptitexPC2
 network-object object GraphicsIMAC2
 network-object object GraphicsDes2
 network-object object JasonWalterPC
 network-object object designstation02
 network-object object CheerPIP02
 network-object object PattExecPC
 network-object object judyh
 network-object object micahw
 network-object object ACCTGSTATION03
object-group network Support
 network-object ITAndrewOffice
 network-object Gateway
 network-object PitneyBowes
 network-object HQCafeKiosk
 network-object object ITAndrewOffice
 network-object object SwannDVR
 network-object object saleslaptop01
 network-object object saleslaptop01wireless
 network-object object ITAndrewPC
 network-object object workstation01
 network-object object Redbox1
 network-object object redbox2
 network-object host Purchase
 network-object object MWSPICEWORKS
 network-object object USERPC
object-group network Laptop
 network-object LewB
 network-object LewBLaptop
 network-object Travel1Wireless
 network-object Travel1laptop
 network-object AbonserLaptopWireless
 network-object AbonserLaptop
 network-object LisaBramesWireless
 network-object LisaBramesWired
 network-object LynnLaptopWireless
 network-object LynnLaptopWired
 network-object BobCorpLaptopWired
 network-object BobCorpLaptopWireless
 network-object host Smartcut
 network-object object jodigym
 network-object object MWLAPTOP2-wired
 network-object object MWLAPTOP2-wireless
 network-object object mwm7laptop1wireless
 network-object object mwm7laptop2wired
 network-object object mww7laptop1wired
 network-object object mww7laptop2wireless
object-group service Web tcp
 port-object eq www
 port-object eq ftp-data
 port-object eq https
 port-object eq ftp
object-group network WebPass
 network-object Webpass2
 network-object Webpass
 network-object Pass3
 network-object Pass4
 network-object Pass5
 network-object Pass6
 network-object WebPassDC
 network-object host Pass2
 network-object object AndrewMPhone
object-group network ExchangeDefender_All
 description All servers in exchange defender group
 network-object ExchangeDefender10
 network-object ExchangeDefender7
 network-object ExchangeDefender4
 network-object ExchangeDefender8
 network-object ExchangeDefender9
 network-object ExchangeDefender3
 network-object ExchangeDefender1
 network-object ExchangeDefender2
 network-object ExchangeDefender5
 network-object ExchangeDefender6
object-group network DistributionCenter
 description Distribution Center
 network-object host DCDBSERVER
 network-object host UPSDC
 network-object host UPSDC2
 network-object host LauraS
 network-object host CarouselPC
 network-object host UPSDCWired
 network-object host UPSDC2wired
 network-object object Pip01
 network-object host SewingOffice
 network-object object AndrewMGalaxyDC
 network-object object DCScreenprint
 network-object object mwworkstation03
 network-object object pickcarousel
 network-object object EMBPRODUCTION01
 network-object object PCDBSVR
 network-object object NEWDCUPS
object-group network Lectra
 description Lectra and Cutting Computers
 network-object host Lectra3
 network-object object LectraEastCut
 network-object object LectraWestCut
 network-object object AlysPlot
 network-object object NewWestCut
object-group network ATT_SEG
 description AT&T Secure Email Gateway Servers
 network-object object MXLOGIC1
 network-object object MXLOGIC2
object-group network TrainingPCs
 description TrainingPCs
 network-object object TrainingPC1
 network-object object TrainingPC2
 network-object object TrainingPC3
 network-object object TrainingPC4
object-group network DM_INLINE_NETWORK_1
 group-object Accounting
 group-object CustomerService
 group-object Design
 group-object Executive
 group-object Laptop
 group-object Servers
 group-object Support
 group-object DistributionCenter
 group-object WebPass
 group-object Lectra
 group-object TrainingPCs
object-group service DM_INLINE_SERVICE_1
 service-object gre
 service-object tcp destination eq pptp
object-group network WeekdayInternet
 description Computers with Weekday Internet Access Only
 network-object object Maintenance
access-list inside_access_in extended permit tcp object Private_MAIL object-group ATT_SEG eq smtp
access-list inside_access_in extended deny tcp any any eq smtp
access-list inside_access_in extended permit ip object-group DM_INLINE_NETWORK_1 any
access-list inside_access_in remark Time Frame Restricted Internet
access-list inside_access_in extended permit ip object-group WeekdayInternet any time-range WeekdayInternet
access-list inside_access_in extended deny ip any any
access-list global_access extended permit ip any any
access-list outside_access extended permit object-group DM_INLINE_SERVICE_1 any host
access-list outside_access extended permit tcp object-group ATT_SEG host eq smtp
access-list outside_access extended permit tcp any host object-group Web
access-list outside_access extended permit tcp any host object-group httppop
access-list outside_access extended permit tcp any host eq 3389
access-list outside_access extended permit tcp any object V2KAppSvr eq 3389
access-list outside_access extended permit tcp any object MWSQLSvr eq 3389
access-list outside_access extended deny ip any any
access-list VISUALVPN_splitTunnelAcl standard permit
access-list VISUALVPN_splitTunnelAcl_1 standard permit
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
mtu guest 1500
ip local pool VISUAL2000_POOL mask
ip local pool VISUAL2000_POOL2 mask
icmp unreachable rate-limit 1 burst-size 1
icmp permit any inside
icmp permit any outside
no asdm history enable
arp timeout 14400
nat (inside,outside) source static NETWORK_OBJ_172.16.1.0_24 NETWORK_OBJ_172.16.1.0_24 destination static NETWORK_OBJ_10.16.17.0_24 NETWORK_OBJ_10.16.17.0_24
object network Private_RDP
 nat (inside,outside) static Public_RDP
object network Private_MAIL
 nat (inside,outside) static Public_MAIL
object network Private_WEB_Server
 nat (inside,outside) static Public_WEB_Server
object network Private_VPN
 nat (inside,outside) static Public_VPN
object network Private_MWSQLSvr_RDP
 nat (inside,outside) static Public_MWSQLSvr_RDP
object network Private_V2Kappsvr_RDP
 nat (inside,outside) static Public_V2Kappsvr_RDP
nat (inside,outside) after-auto source dynamic any interface
nat (guest,outside) after-auto source dynamic any interface
access-group inside_access_in in interface inside
access-group outside_access in interface outside
access-group global_access global
route outside XXXXX65 1
route inside 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http ACCOUNTING inside
http MWHQDC1 inside
http ABBIE inside
http UPSUP inside
http inside
http outside
snmp-server host inside ABBIE community ***** version 2c
snmp-server host inside UPSUP community ***** version 2c
snmp-server location XXXXX HQ
no snmp-server contact
snmp-server community *****
snmp-server enable traps snmp authentication linkup linkdown coldstart
sysopt noproxyarp inside
crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map outside_map interface outside
crypto ca trustpoint ASDM_TrustPoint0
 enrollment self
 subject-name CN=XXXXX-asa
 crl configure
crypto ca certificate chain ASDM_TrustPoint0
 certificate afc8a64d
    3082024c 308201b5 a0030201 020204af c8a64d30 0d06092a 864886f7 0d010105
    05003038 31173015 06035504 03130e6d 6f74696f 6e776561 722d6173 61311d30
    1b06092a 864886f7 0d010902 160e6d6f 74696f6e 77656172 2d617361 301e170d
    31313034 31343131 30383038 5a170d32 31303431 31313130 3830385a 30383117
    30150603 55040313 0e6d6f74 696f6e77 6561722d 61736131 1d301b06 092a8648
    86f70d01 0902160e 6d6f7469 6f6e7765 61722d61 73613081 9f300d06 092a8648
    86f70d01 01010500 03818d00 30818902 818100e3 4ec3aa6a 5f96b798 e74752ee
    301823ab 26eadfe9 6b081108 c36d58f2 afe004a4 614cb8d4 0b409ed1 5a4ca5eb
    e5be5e99 78e3e7cd e402fc02 8e2ed871 c71242c9 a31efa91 54b2bed0 7d92e040
    fddb3779 3726b8c2 135f8a69 c494a539 19961e23 459aa27e 301723e5 5dd0b68c
    97992c5a 8b59514e 6c63dbdb 4a8b18e8 f53d8b02 03010001 a3633061 300f0603
    551d1301 01ff0405 30030101 ff300e06 03551d0f 0101ff04 04030201 86301f06
    03551d23 04183016 8014ad7c d97fb61d b2727a8c 170805a9 72c9e63a 9c0d301d
    0603551d 0e041604 14ad7cd9 7fb61db2 727a8c17 0805a972 c9e63a9c 0d300d06
    092a8648 86f70d01 01050500 03818100 42ae32a2 de9a1282 c8ce7094 75e5f658
    fdd41799 8b8f69b6 96ae51b2 4744af6d 164a6be8 4ea07dbb 07fea596 923eb446
    0e080f0c 020dd67b ab4d5e2f 4708320b 1551caf4 1475f166 f2fcf148 cf761505
    93bba115 0f0b68e2 3ffbf32e de34cefb d1f22327 7aafc491 2c4e4f5e 801d4ca6
    7a9b28a0 39fe9651 1a3ec324 2e4b8e2e
crypto isakmp enable outside
crypto isakmp policy 10
 authentication pre-share
 encryption 3des
 hash sha
 group 2
 lifetime 86400
crypto isakmp policy 30
 authentication pre-share
 encryption 3des
 hash sha
 group 1
 lifetime 86400
telnet ABBIE inside
telnet ACCOUNTING inside
telnet MWHQDC1 inside
telnet UPSUP inside
telnet inside
telnet timeout 5
ssh ABBIE inside
ssh ACCOUNTING inside
ssh MWHQDC1 inside
ssh UPSUP inside
ssh inside
ssh timeout 5
console timeout 0
dhcpd address guest
dhcpd dns interface guest
dhcpd lease 86400 interface guest
dhcpd enable guest

threat-detection basic-threat
threat-detection statistics host
threat-detection statistics port
threat-detection statistics protocol
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
tftp-server inside UPSUP XXXXX-asa
group-policy VISUALVPN internal
group-policy VISUALVPN attributes
 wins-server value
 dns-server value
 vpn-tunnel-protocol IPSec
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value VISUALVPN_splitTunnelAcl_1
 default-domain value XXXXXXXXXXXX
username visual2000 password XXXXXXXXXXXXX encrypted privilege 0
username visual2000 attributes
 vpn-group-policy VISUALVPN
tunnel-group VISUALVPN type remote-access
tunnel-group VISUALVPN general-attributes
 address-pool VISUAL2000_POOL2
 default-group-policy VISUALVPN
tunnel-group VISUALVPN ipsec-attributes
 pre-shared-key *****
class-map inspection_default
 match default-inspection-traffic
policy-map type inspect dns preset_dns_map
  message-length maximum client auto
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect ip-options
  inspect netbios
  inspect rsh
  inspect rtsp
  inspect skinny  
  inspect esmtp
  inspect sqlnet
  inspect sunrpc
  inspect tftp
  inspect sip  
  inspect xdmcp
service-policy global_policy global
prompt hostname context
 profile CiscoTAC-1
  no active
  destination address http
  destination address email
  destination transport-method http
  subscribe-to-alert-group diagnostic
  subscribe-to-alert-group environment
  subscribe-to-alert-group inventory periodic monthly
  subscribe-to-alert-group configuration periodic monthly
  subscribe-to-alert-group telemetry periodic daily
: end
no asdm history enable
Question by:Tom-J-Lael
LVL 20

Expert Comment

by:Patrick Bogers
ID: 40207693

Clients can connect but cannot ping inside the network. Does this mean they only can connect but nothing else? or?

BTW: Please hide your privilege passwords before posting here. (cedxxx) isnt that save to begin with.

Author Comment

ID: 40207945
What I mean is my laptop can succcessfully connect to the VPN from home. The VPN client gets an ip on the network.

The internal subnet at work is

I cannot ping from home, but can ping my laptop fine.

Author Comment

ID: 40207951
I cannot seem to edit my first post. I went through and tried best to make sure I didn't post any identifiable IP's and such.

Accepted Solution

Tom-J-Lael earned 0 total points
ID: 40226432

Did you have any suggestions other than don't put my enable PW's in the body of the post?

Author Closing Comment

ID: 40250397
VPN was fine. I was able to solve the problem by allowing ICMP thorugh firewall. For some reason ICMP wasn't allowed through the VPN.

