RE: [fw-wiz] Cisco Remote Access VPN Problem

From: Paul Melson (pmelson_at_gmail.com)
Date: 09/07/05

  • Next message: David Lang: "Re: [fw-wiz] PIX firewall licensing and beyond (newbie)"
    To: "'Firewall-Wizards'" <Firewall-Wizards@govnet.gov.fj>, <firewall-wizards@honor.icsalabs.com>
    Date: Wed, 7 Sep 2005 14:21:42 -0400
    
    

    Static arp entries using the arp command won't help. Enabling proxy-arp on
    FE0/1 might.

    PaulM

    -----Original Message-----
    Subject: [fw-wiz] Cisco Remote Access VPN Problem

    Hi Folks

    I can get the tunnel successfully established ,the client successfully
    authenticated with RADIUS, SA's formed and virtual ips (from the dmz)
    assigned to the remote vpn client. There's static routes present on the 2600
    to route internal network traffic to the dmz gateway (ie. fw) which
    subsequently has rules to route these vpn traffic inside the internal
    network.

    ...

    As a workaround, i tried putting in some static arp entries on the fw , for
    these virtual ips to point to physical dmz interface of the vpn device The
    ensuring result was that return traffic made it way back to the vpn device,
    but then couldn't get to the actual vpn client :-(

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: David Lang: "Re: [fw-wiz] PIX firewall licensing and beyond (newbie)"

    Relevant Pages

    • Re: VPN Routing Problem
      ... "route print" showed the absence of any path for 172.16.200.0 traffic, which of course is why it was getting routed through the default gateway. ... Of course, when the VPN Server decides to allocate a different IP address to the client, I wonder if the route will once more fail? ... I can't put IP reservations onto the DCHP server associated with the VPN service, so can only influence the range of IP addresses given. ...
      (alt.os.windows-xp)
    • Re: VPN Routing Problem
      ... Adding the correct route via the route ... I've run the ipconfig command on client and server and some ... On the VPN Server subsequent to a successful VPN connection from the vpn ... Results of trying to Ping the KWF6 host by name from the VPN client ...
      (alt.os.windows-xp)
    • RE: Connecting to resources over a SBS 2003 VPN
      ... Now the server is on a different IP range the VPN works perfectly. ... i seem to only be able to connect one client at a time ... the system uses route table to route IP traffics. ...
      (microsoft.public.windows.server.sbs)
    • Re: Adding Static route
      ... The server is a TS server for VPN clients. ... Our VPN does not have a problem because it will route ... back to the external IP of the client but the client cannot get to our ... I was thinking about putting the default gateway on the 172.xxx. ...
      (microsoft.public.windows.server.networking)
    • Re: VPN & FTP Question
      ... that the remote client is XP Pro SP2. ... I'm guessing that it is somethint to do with retaining the "route add" ... > default gateway will be changed to the VPN connection once the VPN ... > simply turn off the Use default gateway on remote host in the TCP/IP ...
      (microsoft.public.windows.server.sbs)