Client VPN to PIX 501

I have setup a PIX 501 for client VPN access and have successfully connected to it and can access the internal LAN. To connect I am using the Cisco VPN client (IPSec). However I am having issues where I cant connect to the VPN site from certain internet connections. From these very sites I am able to connect to other VPN sites but not this one site in particular. Can anyone offer any suggestions as to why I would be able to connect to a VPN site and not another from the same internet connection.

Thanks Rolando

Reply to
Rolando Barberis
Loading thread data ...

can you please give us some moe details about the same. can be many things like port blockage, policies not matching etc.

Reply to
rave

If the sites are behind NAT and you have not set up your PIX 501 with isakmp nat-traversal 20 and if the other sites -have- turned that on [or the equivilent], then you would be able to connect to those other sites but not to the 501.

Reply to
Walter Roberson

To further clarify the config and the behavior......

access resources on Site 1 and Site 2.

VPN Site 1 (501) network 10.1.1.x

VPN Site 2 (501) network 172.1.1.x

Site 2 and can access resources, however it can connect and authenticate to Site 1 however we cant ping or access any of the resources on the 10.1.1.x network.

Any suggestions appreciated.

Reply to
Rolando

Is nat traversal turned on? Is split tunneling turned on? Does the internal IP address range at Connection B happen to be in the 10/8 network? If so, are you using the 'mask' parameter on the ip pool definition on the PIX ?

Reply to
Walter Roberson

Do you know how to set the mask on the IP pool, it does not show mask as a parameter on the address pool statement. When the client connects it is being handed a 255.0.0.0 mask. I believe this is the issue since I can connect from a 192 network but not a 10 network. Does anyone know how to set the mask that is handed to the client on the PIX?

Thanks

Reply to
Rolando

formatting link
If you are running PIX 6.2 then you would need to upgrade in order to get this feature.

Reply to
Walter Roberson

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.