crypto ipsec client ezvpn OFFICE connect acl 102 group key mode network-extension <-- Tried client mode peer x.x.x.x acl 102 username password xauth userid mode local int fa4 crypto ipsec client ezvpn OFFICE int bvi1 crypto ipsec client ezvpn OFFICE inside Current acl 102: 10 permit ip host 10.20.1.200 10.254.100.0 0.0.3.255 20 permit ip host 10.20.1.200 172.21.0.0 0.0.255.255 30 permit ip host 10.20.1.200 172.20.0.0 0.0.255.255 40 permit ip host 10.20.1.200 172.30.0.0 0.0.255.255 50 permit ip host 10.20.1.200 10.125.0.0 0.0.255.255 60 deny ip any any ip nat inside source list 125 interface FastEthernet4 overload 10 deny ip host 10.20.1.200 10.125.0.0 0.0.255.255 20 deny ip host 10.20.1.200 172.20.0.0 0.0.255.255 30 deny ip host 10.20.1.200 172.21.0.0 0.0.255.255 40 deny ip host 10.20.1.200 172.30.0.0 0.0.255.255 50 deny ip host 10.20.1.200 10.1.0.0 0.0.255.255 60 deny ip host 10.20.1.200 10.254.0.0 0.0.252.255 70 permit ip 10.20.0.0 0.0.255.255 any (56 matches) 80 permit ip 192.168.2.0 0.0.0.255 any (102 matches)