<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN client cannot access server on DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709651#M1054308</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Everything works fine now.I added extra lines in the ACS ACL and didn't have any additional problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help Kanishka. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Mar 2007 12:19:34 GMT</pubDate>
    <dc:creator>IgorHamzic</dc:creator>
    <dc:date>2007-03-08T12:19:34Z</dc:date>
    <item>
      <title>VPN client cannot access server on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709645#M1054292</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following problem.I have created a new VPN user on Cisco ACS and allowed him access through downloadable ACL to a server in our inside network and server on the DMZ network.He can ping and access server in our inside network but cannot ping or access the server in DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ-NONAT permit ip 192.168.254.0 255.255.255.0 192.168.252.128 255.255.255.128 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool Users2 192.168.252.193-192.168.252.222&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list DMZ-NONAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 10.64.8.20 xxxx timeout 20&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server RADIUS (inside) host 10.64.8.20 xxxx timeout 20&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;aaa-server AuthInbound protocol radius &lt;/P&gt;&lt;P&gt;aaa accounting match 151 outside RADIUS&lt;/P&gt;&lt;P&gt;aaa accounting match 150 outside TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpngroup myVpnGroup address-pool Users2&lt;/P&gt;&lt;P&gt;vpngroup myVpnGroup dns-server 10.64.8.20&lt;/P&gt;&lt;P&gt;vpngroup myVpnGroup split-tunnel nat0_2&lt;/P&gt;&lt;P&gt;vpngroup myVpnGroup idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup myVpnGroup max-time 86400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ACS ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit ip any host 10.64.8.166 - server on the inside network&lt;/P&gt;&lt;P&gt;permit ip any host 192.168.254.166 - server on the DMZ network&lt;/P&gt;&lt;P&gt;permit icmp any host 10.64.8.166&lt;/P&gt;&lt;P&gt;permit icmp any host 192.168.254.166&lt;/P&gt;&lt;P&gt;deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709645#M1054292</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2020-02-21T09:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot access server on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709646#M1054295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have the subnet 192.168.254.0 in the split tunnel ACL ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2007 21:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709646#M1054295</guid>
      <dc:creator>kaachary</dc:creator>
      <dc:date>2007-03-06T21:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot access server on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709647#M1054299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Part of the nat0_2 ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nat0_2 permit ip 192.168.254.0 255.255.255.0 192.168.252.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm rather new to the PIX configuration so any advice will be useful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2007 21:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709647#M1054299</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2007-03-06T21:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot access server on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709648#M1054302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any Access group applied on the DMZ interface ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2007 21:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709648#M1054302</guid>
      <dc:creator>kaachary</dc:creator>
      <dc:date>2007-03-06T21:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot access server on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709649#M1054304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found this in the DMZ ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in6 deny icmp 192.168.254.0 255.255.255.0 192.168.252.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That explains why there isn't any ping and that I'll have to read even more carefully the  large PIX ACL configuration I inherited.Thanks for the direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anything in there you see that could cause any other problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW I'll add 2 more lines to downloadable ACL that will permit user to access the servers using remote desktop.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2007 22:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709649#M1054304</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2007-03-06T22:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot access server on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709650#M1054305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ACL's are in place, I guess you are good to go. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Please rate if the post helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 10:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709650#M1054305</guid>
      <dc:creator>kaachary</dc:creator>
      <dc:date>2007-03-07T10:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot access server on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709651#M1054308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Everything works fine now.I added extra lines in the ACS ACL and didn't have any additional problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help Kanishka. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 12:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-cannot-access-server-on-dmz/m-p/709651#M1054308</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2007-03-08T12:19:34Z</dc:date>
    </item>
  </channel>
</rss>

