Cisco Systems udp traffic not passing over vpnclient connection to pix ASA 7.2

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
udp traffic not passing over vpnclient connection to pix ASA 7.2 lfnetworking 08-29-06
Posted by lfnetworking on August 29, 2006, 4:24 pm
Please log in for more thread options
Pix running 7.2 terminating connection from latest windows vpnclient
ipsec over tcp, client won't pass udp traffic such as xdmcp. I'm
familiar with the old fixup protocol which I understand is replaced by
MPF traffic inspection logic. But, I was unaware this affects vpn
traffic in any way. And, the default policy should allow for xdmcp

Otherwise, the vpnclient setup is as follows...

group-policy * attributes
dns-server value x.x.x.x
vpn-idle-timeout none
ipsec-udp enable
ipsec-udp-port 10000
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split-tunnel

...
access-list split-tunnel extended permit ip 192.168.221.0 255.255.255.0
192.168.220.0 255.255.255.0



Any ideas?


class-map inspection_default
match default-inspection-traffic
!
!
policy-map global_policy
class inspection_default
inspect dns maximum-length 512
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp

service-policy global_policy global

Similar ThreadsPosted
udp traffic not passing over vpnclient connection to pix ASA 7.2 August 29, 2006, 4:24 pm
cisco vpn connection to vpn concentrator 3000 not passing web traffic August 21, 2006, 11:44 pm
VPN connection issue; no data passing after connection August 22, 2007, 11:37 am
Passing traffic through an ASA August 2, 2007, 7:29 pm
PIX 515 to PIX 515e not passing traffic May 10, 2006, 12:04 pm
passing wccp traffic via firewall May 25, 2006, 11:04 am
ASA Stops passing traffic but does not crash November 22, 2006, 2:24 pm
ASA5505 not passing inbound TCP traffic (what am I missing)? August 24, 2007, 2:45 pm
show amount of traffic passing throw interface October 18, 2007, 10:41 am
High latency when idle, low latency when passing traffic April 24, 2006, 7:15 pm
Pix to Pix vpn connection will connect but no traffic passed over August 27, 2008, 8:17 am
VPNclient and access to LAN. September 9, 2005, 1:59 pm
VPNclient and PIX515. January 11, 2007, 7:01 am
[LONG] VPNClient - NAT - LAN to LAN tunnel September 19, 2005, 3:48 pm
assigning vpnclient static ip July 11, 2007, 2:59 pm