Cisco Systems Re: Pix 501: VPN client connects but Internet doesen't work

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Re: Pix 501: VPN client connects but Internet doesen't work Jyri Korhonen 08-05-08
Posted by Jyri Korhonen on August 5, 2008, 6:33 am
Please log in for more thread options

> VPN client connects fine, the tunnel is established and I can
> ping the office machines. But internet doesen't work.
>
> vpngroup orbit address-pool v10
> vpngroup orbit dns-server 172.16.1.9
> vpngroup orbit wins-server 172.16.1.11
> vpngroup orbit default-domain orbit
> vpngroup orbit idle-time 1800
> vpngroup orbit password ********

vpngroup split-tunnel access-list


http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/tz.html#wp1099471

"Use the vpngroup split-tunnel command to enable split tunneling on the PIX
Firewall.
Split tunneling allows a remote VPN client or Easy VPN Remote device simultaneous
encrypted access to the corporate network and clear access to the Internet. Using
the vpngroup split-tunnel command, specify the access list name to which to
associate the split tunnelling of traffic. With split tunnelling enabled, the PIX
Firewall downloads its local network IP address and netmask specified within the
associated access list to the VPN client or Easy VPN Remote device as part of the
policy push to the client. In turn, the VPN client or Easy VPN Remote device
sends
the traffic destined to the specified local PIX Firewall network via an IPSec
tunnel
and all other traffic in the clear. The PIX Firewall receives the IPSec-protected
packet on its outside interface, decrypts it, and then sends it to its specified
local network.

If you do not enable split tunneling, all traffic between the VPN client or Easy
VPN Remote device and the PIX Firewall is sent through an IPSec tunnel. All
traffic
originating from the VPN client or Easy VPN Remote device is sent to the PIX
Firewall's outside interface through a tunnel, and the client's access to the
Internet from its remote site is denied."

Similar ThreadsPosted
Re: Pix 501: VPN client connects but Internet doesen't work August 5, 2008, 6:33 am
Re: Pix 501: VPN client connects but Internet doesen't work August 5, 2008, 6:39 am
VPN dial connects, but does not work May 29, 2008, 2:28 pm
PIX VPN Client connects but not traffic passes through April 23, 2007, 11:16 pm
Cisco VPN Client 4.04 Rel to a PIX 506E connects, but no traffic February 14, 2005, 11:31 am
cisco client 4.6 connects, but cannot ping resources August 8, 2006, 12:03 pm
Cisco VPN client connects but can't ping or connect to anything? November 28, 2006, 12:47 am
Cisco vpn client 4.8 connects but cannot send or receive January 18, 2007, 10:45 am
Re: vpn client with wireless card doesn't work August 12, 2005, 5:26 pm
no internet when connected to pix with vpn client August 20, 2006, 2:16 pm
Internet access for VPN client May 8, 2007, 2:13 am
Cannot Ping Internet from VLAN Client August 28, 2008, 9:54 pm
PIX 501 relay client DNS requests out to an internet DNS server? November 17, 2006, 5:43 pm
Cisco VPN connects, but I cant connect to remote servers? November 10, 2005, 8:44 am
My clients connects slowly to my cisco switch September 21, 2006, 6:38 am