Hi, I'm in a customer's office and I'm trying to vpn to my office. I can login using my cisco 4.6 vpn client and it was authenticated ok by my office's vpn cisco concentrator. But the problem is I can not ping / telnet to my office LAN. Can someone tell me what the customer needs to open up in his firewall, so i can access my office LAN >>>?? thanks for your help. J-
VPN to OFFice and access internal LAN
Nov 24, 2005
4 Replies
maybe your HO administrator block the telnet and ping from the office
M.Ammoura
no. all telnet and ping are opened on the customer site and HO site.
After I vpn in, I can not ping my home office servers or browsed the website that's hosted on my home office servers. Where only internal IPs can access the website.
Try setting your VPN to use NAT mode.
The way VPNs work is that a connection is opened on UDP 500 for authentication. That works in alot of cases.
Then, the transport is done either by
- IP protocol 50 (fails at a lot of NAT boxes)
- UDP port 4500 (NAT-T IEFT standard NAT-transparent mode)
- UDP 10000 (Cisco pre-standard NAT friendly mode)
By default, the client uses the non-NAT friendly mode.
"Modify" the connection, and under TRANSPORT select "Enable Transparent Tunneling" and set UDP or TCP, sepending on what your concentratot supports.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required