Hi, I am trying to set up Easy VPN server on a Cisco 837. The client I am using is Cisco VPN Client 4.7. I can establish the tunnle to the Cisco 837, and get an IP address as 192.168.99.x.
As you can see, I use split tunnel. I can ping the public IP address of Cisco 837, as it goes via the existing route. However, I can't ping the ethernet interface (or any PC in the same LAN segment) from my PC eventhough it shows:
Destination Netmask Gateway Interface
192.168.10.0 255.255.255.0 192.168.99.81 192.168.99.81I also did a "debug ip icmp" in Cisco. But when I did "ping
192.168.10.1 -t", I could not see any information from the terminal. It looks like the packet doesn't reach the ethernet interface.Any ideas?
Thanks in advance.
! version 12.3 no service pad service timestamps debug datetime msec service timestamps log datetime msec service password-encryption ! hostname V334 ! boot-start-marker boot-end-marker ! enable password 7 12345 ! username vpn password 7 12345 aaa new-model ! ! aaa authentication login userauthen local aaa authorization network groupauthor local aaa session-id common ip subnet-zero ! ! ip dhcp excluded-address 192.168.10.2 192.168.10.99 ! ip dhcp pool genetech network 192.168.10.0 255.255.255.0 dns-server 202.X.X.X default-router 192.168.10.1 ! ! ip ips po max-events 100 no ftp-server write-enable ! ! ! ! ! crypto isakmp policy 1 encr 3des hash md5 authentication pre-share group 2 ! crypto isakmp client configuration group vpn key 12345 dns x.x.x.x pool vpnpool acl 120 ! ! crypto ipsec transform-set genetech esp-3des esp-sha-hmac ! crypto dynamic-map dynmap 10 set transform-set genetech reverse-route ! ! ! crypto map genetech client authentication list userauthen crypto map genetech isakmp authorization list groupauthor crypto map genetech client configuration address respond crypto map genetech 10 ipsec-isakmp dynamic dynmap ! ! ! interface Ethernet0 ip address 192.168.10.1 255.255.255.0 ip nat inside ip virtual-reassembly hold-queue 100 out ! interface Ethernet2 no ip address shutdown hold-queue 100 out ! interface ATM0 no ip address no atm ilmi-keepalive dsl operating-mode auto dsl power-cutback 1 pvc 8/35 encapsulation aal5mux ppp dialer dialer pool-member 1 ! ! interface FastEthernet1 no ip address duplex auto speed auto ! interface FastEthernet2 no ip address duplex auto speed auto ! interface FastEthernet3 no ip address duplex auto speed auto ! interface FastEthernet4 no ip address duplex auto speed auto ! interface Dialer1 ip address negotiated no ip redirects no ip unreachables ip mtu 1492 ip nat outside ip virtual-reassembly encapsulation ppp dialer pool 1 dialer-group 1 no cdp enable ppp chap hostname snipped-for-privacy@abc.com.au ppp chap password 7 12345 crypto map genetech ! interface Dialer0 no ip address ! ip local pool vpnpool 192.168.99.80 192.168.99.90 ip classless ip route 0.0.0.0 0.0.0.0 Dialer1 ! no ip http server no ip http secure-server ! ip nat inside source list 110 interface Dialer1 overload ip nat inside source static tcp 192.168.10.100 25 interface Dialer1 25 ip nat inside source static tcp 192.168.10.6 21 interface Dialer1 21 ip nat inside source static udp 192.168.10.6 53 interface Dialer1 53 ip nat inside source static tcp 192.168.10.6 53 interface Dialer1 53 ip nat inside source static tcp 192.168.10.6 22 interface Dialer1 22 ip nat inside source static tcp 192.168.10.6 80 interface Dialer1 80 ! ! access-list 10 permit 192.168.10.0 0.0.0.255 access-list 10 deny any access-list 110 deny ip 192.168.10.0 0.0.0.255 192.168.99.0 0.0.0.255 access-list 110 permit ip 192.168.10.0 0.0.0.255 any access-list 110 permit ip host 10.1.28.13 any access-list 120 permit ip 192.168.99.0 0.0.0.255 any access-list 120 permit ip 192.168.10.0 0.0.0.255 any dialer-list 1 protocol ip permit ! ! control-plane ! ! line con 0 password 7 12345 no modem enable transport preferred all transport output all line aux 0 transport preferred all transport output all line vty 0 4 access-class 10 in password 7 12345 transport preferred all transport input all transport output all ! scheduler max-task-time 5000 end