Cisco VPN :: PIX 6.3 Remote Client VPN / Traffic One Way Only

Sep 20, 2012

I have a few ASAs with L2Ls in a hub-and-spoke fashion, works great. All ASAs are 8.2(1). I've tried to add remote-vpn to the HQ ASA. I have this working on a PIX 6.3 box at HQ, but have not been able to make it work completely on the ASA.
 
Just to check, I also set up remote client vpn access on one of the spoke ASAs, and that actually did go well. Applying the equivalent config on the HQ ASA - won't function.
 
The problem with the HQ ASA remote client vpn is that after completed phase 1 & 2, the traffic goes one way only, from client side towards the ASA. I e remote side only encaps, no decaps; ASA side only decaps, no encaps. If the remote client pings a host on the inside (i e behind the HQ ASA) the packets arrive, and are returned towards the ASA (a correct route for the remote vpn network is in place on the inside host). However, it seems as if the ASA doesn't send that traffic back into the tunnel, but rather sends it unencrypted through the default route (doing a traceroute from the inside host for instance suggests this).
 
The ONLY way I can pass traffic towards the remote client is by initiating a ping from within the HQ ASA, it's the only time I get encaps on the ASA side and decaps on the remote side of the tunnel. Interestingly, it's actually the "ping outside 192.168..." that works, doing an "inside" ping fails. Compare this to the spoke ASA and its remote vpn client, there an inside ping is succesful, but not a outside ping, i e the spoke ASA functions as expected with its remote vpn. Given that the configs on the two ASAs are the same for remote client access, I would have expected both to work, not only one of them. But then, the HQ ASA has more lines of code, and I guess that something there gets in the way. [code]

View 7 Replies


ADVERTISEMENT

Cisco VPN :: 876 ISR / Traffic From Easy VPN Client To Remote End Of Site-to-site?

Apr 27, 2011

A user with Easy VPN client connects to a 876 ISR (router A). This router also has a site-to-site VPN to another 876 ISR (router B). What I want to achieve is that the user dials in to router A and can access the network on the remote end of the site-to-site tunnel (router B) In diagram:
 
user (192.168.18.x) - Easy VPN - Router A (192.168.16.x) - sitetosite - Router B (192.168.17.x)
 
I have added routes in router B to the 192.168.18.x network with router A as next hop, but I can't reach the other segment.

View 1 Replies View Related

Cisco VPN :: VPN Client Traffic Through ASA 5500?

Feb 10, 2011

I have been trying to conect a Cisco VPN client through an ASA and it makes the connection but doesn't allow any traffic through. The ASA does have a site to site VPN attached to the outside interface.I suppose the first question is it possible to allow VPN client to connect through an ASA 5500 from the inside network when there are Site to Site VPN's already attached to the outside interfaces?If possible then what have I missed. I have tried adding NAT exempt for the traffic between the internal networks and "an IPSEC pass thru Inspect Map".

View 4 Replies View Related

Cisco VPN :: 878 / Multicast Traffic Over Client Vpn

Feb 10, 2012

i already created a vpn server on my 878 router.. so that i can connect with ip-sec (cisco vpn client) to this router and network..
 
all working great... however... when i also want to allow multicast traffic over my vpn connection. do i then need a GRE vpn? or what?or is this only needed when you use a site to site vpn..?And how can i enable this?

View 3 Replies View Related

Cisco :: Client Behind NAt Access Remote Desktop?

Jan 22, 2011

I have A setup in different location with the the ASA Firewall with VPN enabled and a Print server. on Network B i have a server with 2008 installed and its my NAT server, DNS and File server.Now the Client on Netwrok B wants to access the Server in Network A Remotely through VPN they could connect to but cannot user Remote Desktop either its Ip translation issue or i dont know.

View 2 Replies View Related

Cisco VPN :: Client Behind EzVPN Remote (ASA 5505)?

Feb 2, 2012

I try to configure a simple EzVPN infrastructure:
 
EzVPN Server (CISCO2811, hostname cme) < -- > EzVPN Remote (ASA5505, hostname ezvpn-asa) < -- > Client
 
Attached you find both configuration of the EzVPN server and remote. The tunnel is getting up and if I ping from the ASA to the Router, I see the packets getting encrypted:
 
ezvpn-asa# ping 172.16.100.1
...
ezvpn-asa# show crypto ipsec sa
interface: outside
Crypto map tag: _vpnc_cm, seq num: 10, local addr: 172.16.100.2

[code]....
 
If I connect a client with IP address 192.168.1.2 to the interface eth0/1 and do a ping to the cme, I don't see any packets getting encrypted. I don't have any idea about VPN, I just need it for a wireless lab environment. What do I have to configure on the ASA, so the inside traffic is encrypted?

View 2 Replies View Related

Cisco VPN :: 2911 ISR Remote Client Connects Just Once?

Feb 2, 2011

After trying to configure remote client VPN access to a Cisco 2911 ISR using the CLI I tried to use the Cisco Configuration Professional. However, either way I have the same problem. A client can successfully connect and access servers but just once. When the client disconnects and tries to connect again there is no access to the servers even though the VPN tunnel appears to be up. I've tried multiple versions of the Cisco vpn client SW and all behave the same: 1st connection can access servers, subsequent connections can't. I've also tried a second (different) client after the original connection and still no luck. If I reload the router the client can get the vpn connection and access the servers but if the client disconnects from the vpn and tries again there is no access to the servers.
 
I've also tried it with and without NAT but it doesn't seem to make any difference.
 
The config generated using CCP is as follows:
 
version 15.0
service timestamps debug datetime msec
service timestamps log datetime msec

[Code].....

View 4 Replies View Related

Cisco VPN :: ASA 5505 - VPN Client Will Not Access Remote Lan

Mar 10, 2013

I have an ASA 5505 that is on the perimeter of a hub & spoke vpn network, when I connect to this device using the VPN client I can connect to any device across the VPN infrastructure with the exception of the sub net that the client is connected to, for instance:
 
VPN client internal network connects to 192.168.113.0 /24 and is issued that ip address 192.168.113.200, the VPN client can be pinged from another device in this network however the client cannot access anything on this sub net, all other sites can be accessed ie. main site 192.168.16.0/24, second site 192.168.110/24 and third site 192.168.112/24. The ACL Manager has a single entry of  "Source 192.168.113.0/24 Destination 192.168.0.0/16 and the "Standard ACL 192.168.8.8./16 permit.

View 14 Replies View Related

Cisco VPN :: 2811 / Remote VPN Client Is Not Communicating With LAN?

Apr 19, 2011

I have a cisco 2811 with security bundle with IOS 12.4(13r)T I am planing to use this router as a VPN gateway for company ( i.e)
 
1. LAN 2 LAN VPN ( Supporting if remote site is having dynamic IP)

2. Remote access VPN for VPN client 
 
I have configured the router ( attached is the configuration) I have not tried to use the LAN to LAN VPN ( first i complete remote access VPN and then check L2L) I tried to use the remote access VPN I am able to connect from vpn client software and got the IP address but unable to ping the servers in LAN.

View 13 Replies View Related

2x Client On Android To Remote Into Desktop

May 25, 2012

This is probably where I should have started my search. During the last 2 days I have taught myself numerous things to try and figure out this problem. I want to run 2x Client on my android to remote into my desktop. I have a Verizon fios actiontec router ver. I and running win 7 prof.. I have been able to easily set up the 2x client and remote into my desktop while on my home wifi but trying to use 3g/4g service has yielded nothing but heartache and stress.

View 4 Replies View Related

Cisco :: VPN Client Traffic Encrypted Check

Oct 12, 2012

How can we check when we connect using VPN client software if traffic is getting encrypted ?

View 7 Replies View Related

How To Allow Port 80 Net Remote Traffic

May 8, 2012

I have a game launcher who do not want to update because:"The system is unable to connect to the update server url... The Windows operating system has a proxy redirecting port 80 to your local machine port 8877.If you have a real proxy, make sure it is configured to allow port 80 .NET remoting traffic. If you do not have a proxy, you may have leftover problems from malware in which case you will have to disable the proxy on your machine."i have made many tests and i have no malware and no proxy! so as the error message says, the problem is because the port 80 is not allowed .NET remoting traffic, how do i allow it ?

View 2 Replies View Related

Cisco :: Does IOS Tftp Client Support Remote Symlinks

Mar 27, 2012

Question is in the subject line. Maybe I am missing something, but this does not seem to work (No such file or directory).

View 3 Replies View Related

Cisco :: Remote Vpn Client To Router With Cellular Interface?

Apr 28, 2011

I'm having extreme issues in getting my vpn client to connect to a cisco router with a hwic-3g-hspa cellular interface

I have tested the config remotely by traversing the tunnel I have setup with a cisco vpn client and the client does connect, however when out on the road it doesn't respond, I'm litterally hitting my head against a brick here, everything just seem right I can't explain it.

I have done debugs and there is no sign of life, its as though when the vpn client connects to the router its not responding any way here is my config for the vpn clients part that is.

aaa new-model
!
!
aaa group server radius vpn-client-server-group-1

[Code].....

View 2 Replies View Related

Cisco :: Set Up A SSL VPN Connection For Remote Connectivity With AnyConnect Client?

Jun 28, 2011

I've been trying to set up a SSL VPN connection for remote conenctivitiy with AnyConnect Client. I've configured virtually everything necessary, I can connect to the VPN page, download the Client, establish connectivity, Get an internal-IP address. But I can't ping any internal (and of course external IP addresses)

View 12 Replies View Related

Cisco VPN :: ASA 5510 Access All Branches Using Remote Client

Jun 18, 2011

I am having asa 5520 in my head office and in branches 2811 routers.i connected two branches with my HO through VPN.now i configured remote vpn client in HO asa . now i need to access all the branches using this remote client.how i create route in HO ASA.

View 7 Replies View Related

Cisco VPN :: Remote IPSec VPN - Windows 7 Client And ASA 5505?

Dec 20, 2011

I have difficulties with configuring Remote IPSec VPN with Cisco ASA 5505 and Windows 7 native VPN client. My client PC gets VPN pool IP address, and can access remote network behind ASA, but then I lose my internet connectivity. I have read that this should be an issue with split tunneling, but I did as it is told here and no luck.On Windows VPN Client settings, if I uncheck "use default gateway on remote network" I have internet connectivity (since client is using local gateway), but then, I cannot ping remote network.In log, I see this warnings of this type:Teardown TCP connection 256 for outside:192.168.150.1/49562 to outside:213.199.181.90/80 duration 0:00:00 bytes 0 Flow is a loopback (cisco)I have attached my configuration file (without split-tunneling configuration I tried). If you need additional logs I'll send them right away.

View 4 Replies View Related

Cisco VPN :: ASA 5550 - Can Client Establish SSL To Remote Network

Mar 16, 2012

Device asa 5550 - But can a Client establish a SSL VPN  to remote network and devices on the remote network access local network printers? so you got one client one network A that creates a SSL VPN  to network B , can network B be configured so that automatic job come across the same ssl vpn to a Different IP?

View 5 Replies View Related

Cisco VPN :: 887 - EasyVPN Client Cannot Access Remote LAN But Only Router?

Oct 26, 2010

I am using Cisco configuration professional to set up one easy vpn server on 887-K9,vpn client can dial up the server successfully but can only ping router but on other lan. Looks like there is a nat issues between lan and vpn client?

View 5 Replies View Related

Cisco VPN :: 3000 - How To Generate PCF File For Remote SW Client

Oct 10, 2011

I can't seem to find out how I can generate a PCF file for a new remote vpn SW client? I have a VPN Concentrator 3000 series.

View 1 Replies View Related

Cisco VPN :: 5510 Remote Access VPN / Ping From Client

Jul 26, 2011

I'm configuring ASA 5510 Remote Access VPN, I can connect from Cisco VPN Client to the ASA VPN. I obtain from ASA some routes to inside networks, but I can't do any ping to those inside hosts. I have got those error in ASDM log file: [code]

View 1 Replies View Related

Cisco VPN :: ASA 5540 - Client On Windows 7 With No Remote Access

Feb 22, 2011

Recently i have received one of my collegue's laptop that is running windows 7.I have installed cisco VPN client version 5.0.07.0290 on it and  VPN client appears to connect to our ASA5540, but we are unable to connect (remote desktop) to any machines on our network as it does on our XP laptops.  Furthermore, we cannot ping any as well.  Also, while connected the Windows 7 machine is still able to access internet site as if split-tunneling was configured, which its not.
 
But after some searching , i found from "routeprint" output (shown below ) that my local internet gateway is prefered over the VPN gateway which is 10.10.4.1.Here 10.10.4.19 is the IP address assigned for VPN adaptor.
 
Network Destination        Netmask          Gateway       Interface  Metric          0.0.0.0                    0.0.0.0      192.168.1.1      192.168.1.2     25          0.0.0.0                    0.0.0.0        10.10.4.1       10.10.4.19    100
 
But after i manually add the below route on windows 7 laptop , it started connecting to remote desktop successfully.
 
route change 0.0.0.0 mask 0.0.0.0 10.10.4.1 metric 20
 
But aftersome time of idle state , it is again going back to original route state of prefering the local gateway of 192.168.1.2 and thus unable to connect to Remote Desktop again.

View 3 Replies View Related

Cisco VPN :: 5505 Using VPN Client To Access Remote Network Over L2l

Apr 3, 2013

I´m tring to configure ASA 5505 with VPN Cleint,  to access a remote network over a L2L with another ASA 5505, but no sucess. Is there any special feature to this work?

View 2 Replies View Related

Cisco VPN :: ASA 5505 / 5510 - VPN Client Accessing Remote LAN

Apr 2, 2012

Trying to figure out how to configure the VPN client side to access a remote LAN.
 
Lan A - 172.16.17.0 - ASA5505 8.2(3)
Lan B - 200.200.0.0 - ASA5510
Cisco Client - V5
 
At present there exist a VPN tunnel between LAN A and LAN B. The client has a VPN tunnel to LAN A to run software package X on the LAN A server. The client also needs to run software package Y which needs access to a database on LAN B.  The computers on LAN A have no problem using package Y since a VPN tunnel exist between LAN A and LAN B. How can I get the Client to also access LAN B on the same tunnel created when the client connects to LAN A? I can't seem to get packets that are directed to LAN B to cross the Client tunnel to A which would then hopefully move onto the LAN A/ LAN B tunnel.

View 2 Replies View Related

Cisco Firewall :: Remote VPN User Client Type On ASA 8.3?

Jun 21, 2011

It seemed that show vpn-sessiondb ra-ikev1-ipsec will not provide the client type of the remote vpn user as show vpn-sessiondb remote did before.
 
Is there a way to find it out on ASA running 8.3?

View 1 Replies View Related

Cisco VPN :: ASA 5510 / VPN Client Cannot Access Remote Servers

Mar 27, 2011

I have successfully installed and configured VPN Client - Version 5.0.07 to connect to ASA 5510 from a remote workstation. Here is the problem, I cannot ping any of the servers or workstations after I successfully connect. I can ping the ASA 5510 using its internal LAN IP, but no other nodes will respond on the remote LAN.

View 2 Replies View Related

Cisco Security :: RDP Access For Remote VPN Client On ASA 5510?

Jan 17, 2011

We have configured site to site VPN tunnel from offshore to client location using ASA5510 and accessing RDP from client location. Also configured remote VPN access at offshore location. But using remote VPN client we are able to get RDP from officeshore location but not able to access RDP from client location. Is there any additional changes required ?

View 4 Replies View Related

Run Remote Desktop Client Using CAT 5 Crossover Isn't Working

Aug 9, 2011

Attempts to run remote desktop client a laptop on a tower using a CAT 5 Crossover isn't working. After starting the remote desktop on the laptop, I'm asked to identify the other computer, which I do, and a remote desktop window with a black background pops up, as expected. But I expect an opportunity to login will be displayed after a second or so. That never happens. After about a minute this pops up:Remote Desktop Disconnected?Your Remote Desktop session has ended.The connection to the remote computer was lost, possibly due to network connectivity problems. Try connecting to the remote computer again. If the problem continues, contact your network administrator or technical support.

My clients are impressed with my ability to setup their networks, Linksys routers with WIFI. But toss something unfamiliar into the mix, like this situation, and I'm pretty lost, pretty quick.

Environment:
Hospital's WIFI.
Laptop running XP Home with WIFI and Ethernet.
Tower running Win 7 Ultra with Ethernet.
Cat 5 crossover cable.

Goal:Configure laptop to access Hospital's WIFI. This is successful, I'm using it to post this. Configure laptop run a remote desktop with the tower as the server. The tower, running Win 7, has no monitor. I don't have a flat screen monitor, and didn't feel like dragging an 80 pound 24 inch Nokia into the hospital.After reading some sites while trying to figure this out, I gave the laptop the same group name, workgroup, as the tower.In my experience, starting the tower has been, turn it on, and it boots to Win 7. But I can't watch that happen without a monitor. I can't configure the the tower's network connections without a monitor either.I purchased the CAT 5 crossover cable yesterday, for this occasion. The label on the plastic bag it was packaged in had the word "Crossover" on it. I connect the CAT 5 to the laptop's single ethernet connection, and to the tower's Intel pro card. At home the laptop is on WIFI, the tower connects to the router.

View 4 Replies View Related

Cisco VPN :: Filter Remote Access Traffic On PIX 501?

Mar 20, 2012

Is it possible to filter remote access VPN traffic on a PIX 501 (like you can on an ASA?)

View 1 Replies View Related

Cisco VPN :: Unable To Use ASA 8.4.2 And U-turn For Remote Traffic?

Mar 13, 2012

I have a problem with ASA 8.4.2 and U turn for remote vpn traffic that needs to exit from Remote VPN and then to make a u turn on outside interface to enter another site to site VPN.
 
Interesting traffic access list is modified as needed, routing is ok, but  debug icmp trace 20 is showing that icmp packet from remote vpn client address to the host on the other side of maintained site to site tunnel is going to the inside - not  to the outside as it should go.
 
Route  
S    172.17.1.2 255.255.255.255 [1/0] via Internet Provider, outside
 ASA# ICMP echo request from outside:172.16.10.149 to inside:172.17.1.2 ID=1 seq=159 len=32
ICMP echo request from outside:172.16.10.149 to inside:172.17.1.2 ID=1 seq=160 len=32
ICMP echo request from outside:172.16.10.149 to inside:172.17.1.2 ID=1 seq=161 len=32
 
Same security intra interface command is entered

View 4 Replies View Related

Cisco Firewall :: ASA 5510 8.4 / VPN Traffic For Specific Client?

Mar 16, 2013

I have ASA 5510 8.4 Firewall where more than 20 Site to Site VPN Clients are configured on it. how to see the traffic for one Specific Site to Site VPN.Actually this site to site vpn is always keep dropping for every minute. I'm sure its a problem at the other end.The remaining 19 VPNS are UP and working without any problem. How to see the traffic for specific vlan.More over we dont have any syslog server in our network. Is their any chance we can check the traffic on the firewall?

View 6 Replies View Related

Cisco :: Client Looking To Segment Traffic Via SSID Using 2504

Nov 28, 2012

I have a client with a WLC 2504 that wants to route "guest" users through a gateway appliance "radiusgateway.com" and all others through the network. It appears to me this would require the use of two fa ports on the WLC. One directly connected to the radiusgateway (which is connected to a switchport) and the other fa interface connected directly to a switchport bypassing the proxy server.
 
My issue is, "how do you segment the ssid traffic via the WLC". The interfaces cia the gui aren't that intelligent, there's an enable and logging drop down. Via the command line, I didn't see any methods of routing traffic.

View 1 Replies View Related

Cisco WAN :: 5510 VPN Traffic Will Not Route For Windows Vpn Client

Jul 31, 2012

I have an ASa 5510 and setup remote dial in users.
 
I wanted to use the windows 7 built in client and also the draytek site to site VPN options however when they connect VPN traffic will not work however when i use the cisco VPN client then everything works fine.
 
All the VPN's connect pretty quickly.In the syslog I a getting errors when i try and ping something: [code]

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved