<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Client is cannot able to connect to the internal network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770077#M1053912</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any thing on the internal network is not reachable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 15 Jul 2007 08:40:04 GMT</pubDate>
    <dc:creator>mkmzaman</dc:creator>
    <dc:date>2007-07-15T08:40:04Z</dc:date>
    <item>
      <title>VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770072#M1053904</link>
      <description>&lt;P&gt;When a remote vpn client connects he can ssh to dmz network but cannot able to do ssh on the internal network.&lt;/P&gt;&lt;P&gt;There are 2 types of VPN are installed. First is Site-site and the second is remote vpnclient. please help me out.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770072#M1053904</guid>
      <dc:creator>mkmzaman</dc:creator>
      <dc:date>2020-02-21T09:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770073#M1053908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you post a sanitized config from the ASA? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the traffic between the inside network and the vpn client subnet exempted from nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any split tunnel configured?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 13:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770073#M1053908</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-07-11T13:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770074#M1053909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list inside_outbound_nat0_acl extended permit ip INSIDE-NET 255.255.255.0 192.168.70.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list dmz_outbound_nat0_acl extended permit ip DMZ-NET 255.255.255.0 192.168.70.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list dmz_outbound_nat0_acl extended permit ip any host 10.1.19.4 &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (inside) 1 INSIDE-NET 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (dmz) 0 access-list dmz_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (dmz) 1 DMZ-NET 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Split tunnel is enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 13:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770074#M1053909</guid>
      <dc:creator>mkmzaman</dc:creator>
      <dc:date>2007-07-11T13:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770075#M1053910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please find attached the configs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 13:53:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770075#M1053910</guid>
      <dc:creator>mkmzaman</dc:creator>
      <dc:date>2007-07-11T13:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770076#M1053911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The config looks ok. The inside network is exempted from nat to the vpn client subnet and is also included in the split tunnel acl. Can you ping any devices on the inside network or is it specifically ssh traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2007 18:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770076#M1053911</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-07-13T18:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770077#M1053912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any thing on the internal network is not reachable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Jul 2007 08:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770077#M1053912</guid>
      <dc:creator>mkmzaman</dc:creator>
      <dc:date>2007-07-15T08:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770078#M1053913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I  tried to SSH to Internal network, the syslog gives the following:&lt;/P&gt;&lt;P&gt;3	Jul 16 2007	18:13:40	713042			IKE Initiator unable to find policy: Intf 1, Src: 192.168.60.10, Dst: 192.168.70.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2007 03:53:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770078#M1053913</guid>
      <dc:creator>mkmzaman</dc:creator>
      <dc:date>2007-07-17T03:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770079#M1053914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp identity address&lt;/P&gt;&lt;P&gt;no crypto map outside_map 40 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is all you should need. I would clean out all the rest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp identity address&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp policy 30&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2007 11:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770079#M1053914</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-07-17T11:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client is cannot able to connect to the internal network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770080#M1053915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Crypto map access list was conflicting with the site-site vpn. i have changed that, it started working.&lt;/P&gt;&lt;P&gt;thanks for the support&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2007 08:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-is-cannot-able-to-connect-to-the-internal-network/m-p/770080#M1053915</guid>
      <dc:creator>mkmzaman</dc:creator>
      <dc:date>2007-07-24T08:43:54Z</dc:date>
    </item>
  </channel>
</rss>

