I am not able to figure out why any of my remote users are not able to connect through the VPN client 4.6 when they are on other networks. If they are on the internet (AOL, MSN, etc...) there is no problem.
Any help?? I am a noob so speak slowly because I have to use the interface manager.
~noob~
Didn't find your answer? Ask the community — no account required.
C
Chad Mahoney
Well some config files, logfiles, error files from both firewall and client and firewall software revision would help.
But if I understand you right, when your clients go to another network they can not access the VPN, but when they are internet they can?
The internet is another network so what is the difference between the sites they can connect from and the sites they can not connect from? Are these client sites? If so they may deny IPSEC out of their network for security purposes.
N
Noob
Well here is what I have for my configs and some more answers. I did change the IP's around cause I am paranoid. Thansk for the help btw
Yes, only when they do not have to go through someones network. I am not sure why they are able to connect with out any problems when they are going through earthlink, AOL or any of those.
You come to any network I control and you will be lucky to even get an IP address. Let me ask you,
How bout when I come to your network and create a VPN tunnel, then my network is now exposed to yours and vice-versa.
C
Chad Mahoney
Not sure, have you contacted them?
Their network, their rules...
N
Noob
I called and talked to the them, they said that IPSEC was allowed but will check to make sure that their "Internet Connection Sharing" was set correctly. I am thinking that this might be the problem.
I have also talked to a few more outside sales people. Seems that only some are having this problem at a few clients locations. I like how a few turns into everyone.
N
Newbie72
I was a noob once upon a time to.
formatting link
ICS and the Cisco VPN client will not work. Google has been my friend for many configuration questions.
formatting link
is your best firend. Some of the topics require a login. If are a noob then the best suggestion I can make to you is buy a support contract from Cisco until you are comfortable. their support is great and when you are in a pinch you can call and the answers you need.
One piece of advice I can give you is never give out your real addresses to any forum over the net. It provokes young kids in Denmark to want to hack or throw a DOS attack at you.
Steve
N
Newbie72
A general rule of thumb is if you enable any kind of admin access on an external interface you could be asking for trouble and heavily guard and monitor it. Especially now that everyone on the internet has the ip address they need to spoof to get access
ssh 63.160.66.0 255.255.255.0 outside
N
Noob
ok, now I feel like a twit. I am not sure why any one needs admin access from the external interface. How do I change it?
N
Noob
formatting link
I thought I changed all of them. I REALLY am a noob. any help on this?
N
Noob
formatting link
I thought I changed all of them. I REALLY am a noob. any help on this?
N
Noob
I hope I removed it but i think it might be a little to late..
How do I remove admin access from the outside interface?
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.