Simultaneous users making a VPN connection from one location

We have a Cisco PIX firewall with version 6.1.

I am having an issue with simultaneous users making a VPN connection to the corporate office from a remote location. One pc can make the VPN connection ok, but when the other pc at that same location makes the connection, the first pc gets knocked off. I have noticed that the IP address taken from the IP pool is the same for both PC's, which is part of the issue.

I have read through user's posts and found that we need isakmp nat-traversal enabled, however we are on firmware version 6.1, not 6.3, and 6.1 does not support this command

Are their any alternatives to upgrading to 6.3 or later to help fix this issue? Is their something in version 6.1 we can do to get this to work correctly?

Thanks in advance.

Gary

Reply to
glac
Loading thread data ...

Yup.

Yup.

If you do not have nat-traversal as a possibility, then you have several choices:

1) Have a large enough global address pool that each user is given a unique public address at the time they form the VPN connection; or 2) Configure the VPN endpoint to use TCP 10000; the Cisco VPN client is supposed to be able to figure that one out (it might need a hint or two). The VPN endpoint would need to be a Cisco VPN Concentrator, or Cisco ASA or Cisco PIX running 7.something (and for the last two I'm going by memory of an option I saw when I was looking for something else completely); or 3) find a different VPN client and endpoint that encapsulate into UDP or TCP; PPTP or L2TP will *not* solve the problem; or 4) use a Cisco ASA or PIX 7.something endpoint and configure for SSL VPN with a java client; or 5) use a Cisco ASA or PIX 7.something endpoint and configure for WebVPN with no client necessary to install.
Reply to
Walter Roberson

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.