<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic remote access VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260832#M1060273</link>
    <description>&lt;P&gt;I have a site to site VPN currently in place.  I am using a 2600 on my side.  I now need to get remote access for home users implemented.  I am getting error:   412:  Secure VPN terminated by locally by client. Remote peer no longer responding.&lt;/P&gt;&lt;P&gt; Below is my config.&lt;/P&gt;&lt;P&gt;Current configuration : 3940 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname scpa&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging queue-limit 100&lt;/P&gt;&lt;P&gt;no logging console&lt;/P&gt;&lt;P&gt;enable secret xxx&lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username ***** password xxxx&lt;/P&gt;&lt;P&gt;memory-size iomem 15&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login userauthen local&lt;/P&gt;&lt;P&gt;aaa authorization network groupauthor local&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip inspect name scpa udp&lt;/P&gt;&lt;P&gt;ip audit notify log&lt;/P&gt;&lt;P&gt;ip audit po max-events 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 1&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 43200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 2&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt;crypto isakmp key ********* address 128..x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp client configuration group sriclient&lt;/P&gt;&lt;P&gt; key sriremote&lt;/P&gt;&lt;P&gt; dns *******&lt;/P&gt;&lt;P&gt; domain ********&lt;/P&gt;&lt;P&gt; pool ippool&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set menlo esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set sriremote esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto dynamic-map dynmap 10&lt;/P&gt;&lt;P&gt; set transform-set sriremote&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map scpa client authentication list userauthen&lt;/P&gt;&lt;P&gt;crypto map scpa isakmp authorization list group&lt;/P&gt;&lt;P&gt;crypto map scpa client configuration address respond&lt;/P&gt;&lt;P&gt;crypto map scpa 1 ipsec-isakmp&lt;/P&gt;&lt;P&gt; set peer 128.x.x.x&lt;/P&gt;&lt;P&gt; set transform-set menlo&lt;/P&gt;&lt;P&gt; set pfs group1&lt;/P&gt;&lt;P&gt; match address 110&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no voice hpi capture buffer&lt;/P&gt;&lt;P&gt;no voice hpi capture destination&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mta receive maximum-recipients 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; description SCPA inside private address&lt;/P&gt;&lt;P&gt; ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip access-group 102 out&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip inspect scpa in&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; description SCPA external address&lt;/P&gt;&lt;P&gt; ip address x.x.x.52 255.255.255.224&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt; crypto map scpa&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip local pool ippool 10.0.0.1 10.0.0.20&lt;/P&gt;&lt;P&gt;ip nat pool ipsec x.x.x.57 199.234.154.57 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;ip nat inside source route-map internet interface FastEthernet0/1 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map ipsec pool ipsec overload&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.0.5 80 interface FastEthernet0/1 80&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.0.5 25 interface FastEthernet0/1 25&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.0.5 443 interface FastEthernet0/1 443&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 199.234.154.33&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip 192.168.0.0 0.0.0.255 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip 192.168.0.0 0.0.0.255 10.0.0.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 192.168.0.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny   53 any any&lt;/P&gt;&lt;P&gt;access-list 101 deny   55 any any&lt;/P&gt;&lt;P&gt;access-list 101 deny   pim any any&lt;/P&gt;&lt;P&gt;access-list 101 deny   ip host 10.0.0.0 any&lt;/P&gt;&lt;P&gt;access-list 101 deny   ip host 192.168.0.0 any&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 eq www&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 eq smtp&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 eq 443&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 established&lt;/P&gt;&lt;P&gt;access-list 101 permit udp host 128.18.241.1 host 199.234.154.57 eq isakmp&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 128.18.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any any eq telnet&lt;/P&gt;&lt;P&gt;access-list 102 deny   ip host 199.234.154.53 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;access-list 102 permit ip any any&lt;/P&gt;&lt;P&gt;access-list 105 permit ip 192.168.0.0 0.0.0.255 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;access-list 110 permit ip host 199.234.154.57 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map internet permit 10&lt;/P&gt;&lt;P&gt; match ip address 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map ipsec permit 10&lt;/P&gt;&lt;P&gt; match ip address 105&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;snmp-server community scpa_public RO&lt;/P&gt;&lt;P&gt;snmp-server enable traps tty&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;call rsvp-sync&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mgcp profile default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dial-peer cor custom&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; password xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody tell what is wrong?   I am using the VPN client 4.0&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:11:08 GMT</pubDate>
    <dc:creator>marc.reed</dc:creator>
    <dc:date>2020-02-21T07:11:08Z</dc:date>
    <item>
      <title>remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260832#M1060273</link>
      <description>&lt;P&gt;I have a site to site VPN currently in place.  I am using a 2600 on my side.  I now need to get remote access for home users implemented.  I am getting error:   412:  Secure VPN terminated by locally by client. Remote peer no longer responding.&lt;/P&gt;&lt;P&gt; Below is my config.&lt;/P&gt;&lt;P&gt;Current configuration : 3940 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname scpa&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging queue-limit 100&lt;/P&gt;&lt;P&gt;no logging console&lt;/P&gt;&lt;P&gt;enable secret xxx&lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username ***** password xxxx&lt;/P&gt;&lt;P&gt;memory-size iomem 15&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login userauthen local&lt;/P&gt;&lt;P&gt;aaa authorization network groupauthor local&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip inspect name scpa udp&lt;/P&gt;&lt;P&gt;ip audit notify log&lt;/P&gt;&lt;P&gt;ip audit po max-events 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 1&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 43200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 2&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt;crypto isakmp key ********* address 128..x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp client configuration group sriclient&lt;/P&gt;&lt;P&gt; key sriremote&lt;/P&gt;&lt;P&gt; dns *******&lt;/P&gt;&lt;P&gt; domain ********&lt;/P&gt;&lt;P&gt; pool ippool&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set menlo esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set sriremote esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto dynamic-map dynmap 10&lt;/P&gt;&lt;P&gt; set transform-set sriremote&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map scpa client authentication list userauthen&lt;/P&gt;&lt;P&gt;crypto map scpa isakmp authorization list group&lt;/P&gt;&lt;P&gt;crypto map scpa client configuration address respond&lt;/P&gt;&lt;P&gt;crypto map scpa 1 ipsec-isakmp&lt;/P&gt;&lt;P&gt; set peer 128.x.x.x&lt;/P&gt;&lt;P&gt; set transform-set menlo&lt;/P&gt;&lt;P&gt; set pfs group1&lt;/P&gt;&lt;P&gt; match address 110&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no voice hpi capture buffer&lt;/P&gt;&lt;P&gt;no voice hpi capture destination&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mta receive maximum-recipients 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; description SCPA inside private address&lt;/P&gt;&lt;P&gt; ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip access-group 102 out&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip inspect scpa in&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; description SCPA external address&lt;/P&gt;&lt;P&gt; ip address x.x.x.52 255.255.255.224&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt; crypto map scpa&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip local pool ippool 10.0.0.1 10.0.0.20&lt;/P&gt;&lt;P&gt;ip nat pool ipsec x.x.x.57 199.234.154.57 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;ip nat inside source route-map internet interface FastEthernet0/1 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map ipsec pool ipsec overload&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.0.5 80 interface FastEthernet0/1 80&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.0.5 25 interface FastEthernet0/1 25&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.0.5 443 interface FastEthernet0/1 443&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 199.234.154.33&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip 192.168.0.0 0.0.0.255 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip 192.168.0.0 0.0.0.255 10.0.0.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 192.168.0.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny   53 any any&lt;/P&gt;&lt;P&gt;access-list 101 deny   55 any any&lt;/P&gt;&lt;P&gt;access-list 101 deny   pim any any&lt;/P&gt;&lt;P&gt;access-list 101 deny   ip host 10.0.0.0 any&lt;/P&gt;&lt;P&gt;access-list 101 deny   ip host 192.168.0.0 any&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 eq www&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 eq smtp&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 eq 443&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 199.234.154.52 established&lt;/P&gt;&lt;P&gt;access-list 101 permit udp host 128.18.241.1 host 199.234.154.57 eq isakmp&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 128.18.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any any eq telnet&lt;/P&gt;&lt;P&gt;access-list 102 deny   ip host 199.234.154.53 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;access-list 102 permit ip any any&lt;/P&gt;&lt;P&gt;access-list 105 permit ip 192.168.0.0 0.0.0.255 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;access-list 110 permit ip host 199.234.154.57 128.18.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map internet permit 10&lt;/P&gt;&lt;P&gt; match ip address 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map ipsec permit 10&lt;/P&gt;&lt;P&gt; match ip address 105&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;snmp-server community scpa_public RO&lt;/P&gt;&lt;P&gt;snmp-server enable traps tty&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;call rsvp-sync&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mgcp profile default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dial-peer cor custom&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; password xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody tell what is wrong?   I am using the VPN client 4.0&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260832#M1060273</guid>
      <dc:creator>marc.reed</dc:creator>
      <dc:date>2020-02-21T07:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260833#M1060275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First things first, I strongly suggest you change your key under the VPN group (&lt;B&gt;key sriremote&lt;/B&gt;), since you have pasted your group name and password, and the IP address of your router in here.  All someone has to do is guess the local username you have configured on this router (the password is easy to find) and they'll be into your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the problem here is your access-list 101 is not allowing these packets in.  Try taking it off the interface temproraily and try a client connection.  If it works then we know that's the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To allow VPN clients in you'll have to add something like the following:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host 199.234.154.52 eq isakmp&lt;/P&gt;&lt;P&gt;access-list 101 permit esp any host 199.234.154.52&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and just in case the client and router negotiate UDP encapsulation (NAT-T):&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host 199.234.154.52 eq 4500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and also allow the unencrypted form of the traffic in:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 10.0.0.0 0.0.0.31 192.168.0.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to specify "any" as the source address cause you don't know the IP address of the VPN client. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2004 02:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260833#M1060275</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-01-08T02:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260834#M1060276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;I have since got it working.  Yes the VPN group, names etc, I just added in there to post here.  I just used a simple word for this example.  But good point!  Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also had to add the line&lt;/P&gt;&lt;P&gt;ip access-list extended protocol&lt;/P&gt;&lt;P&gt;ip access-list extended tunnele-password&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2004 13:16:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260834#M1060276</guid>
      <dc:creator>marc.reed</dc:creator>
      <dc:date>2004-01-08T13:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260835#M1060277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another question if anybody can help??&lt;/P&gt;&lt;P&gt;Yes the "VPN client" did initially work, but it&lt;/P&gt;&lt;P&gt;killed my tunnel for my site to site VPN.  The other side of my VPN is a checkpoint NG.   I have since placed my old original config back in, without the client VPN configurations.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2004 18:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/260835#M1060277</guid>
      <dc:creator>marc.reed</dc:creator>
      <dc:date>2004-01-08T18:39:13Z</dc:date>
    </item>
  </channel>
</rss>

