<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vpn client can'e encrypt packet,VPN up, but no access to ins in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691637#M1037305</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry, but when i start vpn client, I can't see any output on debug!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i make:&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;debug crypto ipsec 255&lt;/P&gt;&lt;P&gt;debug crypto isakmp 255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and after:&lt;/P&gt;&lt;P&gt;try to connect, establishing connection, and pinging..&lt;/P&gt;&lt;P&gt;but on pix no output!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT after &lt;/P&gt;&lt;P&gt;sh crypto ipsec sa &lt;/P&gt;&lt;P&gt;on pix i have this output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;see attachment!&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Dec 2006 17:58:10 GMT</pubDate>
    <dc:creator>daniele.bertolotti</dc:creator>
    <dc:date>2006-12-12T17:58:10Z</dc:date>
    <item>
      <title>Vpn client can'e encrypt packet,VPN up, but no access to inside resources</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691635#M1037296</link>
      <description>&lt;P&gt;at the beginning, i'm sorry for my long message.&lt;/P&gt;&lt;P&gt;i've read here more post about my trouble...but still not foun any solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is about a VPN IPSEC TUNNEL on cisco pix 515e &lt;/P&gt;&lt;P&gt;device. &lt;/P&gt;&lt;P&gt;The pix OS version is 7.0.6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my win xp client have sp2 installed, and try to make vpn tunnel with IPSEC via cisco client 4.6.00.0049 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The strange behavior is:&lt;/P&gt;&lt;P&gt;XP client with Cisco VPN client authenticate itself but can't ping any host of the remote lan. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix is configured with:&lt;/P&gt;&lt;P&gt;PAT on outside interface &lt;/P&gt;&lt;P&gt;and PAT on DMZ interface.&lt;/P&gt;&lt;P&gt;no nat acl for exclude packet sourced from inside network and destinated to vpn pool address.&lt;/P&gt;&lt;P&gt;(this acl haven't any matched when tunnel is up and running)&lt;/P&gt;&lt;P&gt;split tunnel acl for inside lan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i make IPSEC vpn up, and check it via sh crypto ipsec sa i found tunnel active.&lt;/P&gt;&lt;P&gt;when i make sh access-list to check if acl are matched, i found only crypto_dyn20_ acl matched.&lt;/P&gt;&lt;P&gt;nonat acl and splittunnel acl are zero matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i try to ping from client some host on inside network, &lt;/P&gt;&lt;P&gt;nothing appears on stats page on the vpn client.&lt;/P&gt;&lt;P&gt;if i ping from pix to vpn client i see decrypted packet on stats page on client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no encryption appears to be done on client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i try to traceroute from xp client any inside network host, stars appears from first hop..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on my pix i've enabled ipsec-over tcp and&lt;/P&gt;&lt;P&gt;nat-t&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where is my mistake?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please help me! &lt;/P&gt;&lt;P&gt;i'm going crazy!!&lt;/P&gt;&lt;P&gt;i attach my pix config. &lt;/P&gt;&lt;P&gt;thanks a lot . &lt;/P&gt;&lt;P&gt;Daniele &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691635#M1037296</guid>
      <dc:creator>daniele.bertolotti</dc:creator>
      <dc:date>2019-03-11T09:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn client can'e encrypt packet,VPN up, but no access to ins</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691636#M1037300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you think it's possible to post the debug output from following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto ipsec&lt;/P&gt;&lt;P&gt;debug crypto isakmp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2006 16:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691636#M1037300</guid>
      <dc:creator>zulqurnain</dc:creator>
      <dc:date>2006-12-12T16:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn client can'e encrypt packet,VPN up, but no access to ins</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691637#M1037305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry, but when i start vpn client, I can't see any output on debug!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i make:&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;debug crypto ipsec 255&lt;/P&gt;&lt;P&gt;debug crypto isakmp 255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and after:&lt;/P&gt;&lt;P&gt;try to connect, establishing connection, and pinging..&lt;/P&gt;&lt;P&gt;but on pix no output!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT after &lt;/P&gt;&lt;P&gt;sh crypto ipsec sa &lt;/P&gt;&lt;P&gt;on pix i have this output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;see attachment!&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2006 17:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691637#M1037305</guid>
      <dc:creator>daniele.bertolotti</dc:creator>
      <dc:date>2006-12-12T17:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn client can'e encrypt packet,VPN up, but no access to ins</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691638#M1037309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i haven't found solutions..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;someone can help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot to evrybody&lt;/P&gt;&lt;P&gt;daniele&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2006 15:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691638#M1037309</guid>
      <dc:creator>daniele.bertolotti</dc:creator>
      <dc:date>2006-12-13T15:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn client can'e encrypt packet,VPN up, but no access to ins</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691639#M1037312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;maybe solved!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client versioning problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with last version of cisco vpn client (4.8) evrything working well...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2006 16:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691639#M1037312</guid>
      <dc:creator>daniele.bertolotti</dc:creator>
      <dc:date>2006-12-13T16:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn client can'e encrypt packet,VPN up, but no access to ins</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691640#M1037315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;false!&lt;/P&gt;&lt;P&gt;isn't a client problem, but ip addressing problem.&lt;/P&gt;&lt;P&gt;if xp client is behind nat, nothing work.&lt;/P&gt;&lt;P&gt;if xp client has a public ip, no nat, evry thing workin' correcty..also linux via vpnc .. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;obvioulsy pix has:&lt;/P&gt;&lt;P&gt;nat-t enabled via isakmp nat-traversal 20 &lt;/P&gt;&lt;P&gt;command in global configuration, and also&lt;/P&gt;&lt;P&gt;ipsec-over-tcp 10000...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas?&lt;/P&gt;&lt;P&gt;big trouble..&lt;/P&gt;&lt;P&gt;cheers &lt;/P&gt;&lt;P&gt;daniele&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2006 01:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-can-e-encrypt-packet-vpn-up-but-no-access-to-inside/m-p/691640#M1037315</guid>
      <dc:creator>daniele.bertolotti</dc:creator>
      <dc:date>2006-12-14T01:07:48Z</dc:date>
    </item>
  </channel>
</rss>

