<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing local addresspool for IPsec issue on PIX506E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153646#M861161</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the rating.  Sorry I'm not sure about the downloadable ACL.  However I did see this after a quick search&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://supportwiki.cisco.com/ViewWiki/index.php/Downloadable_ACLs_configured_on_the_Cisco_Secure_ACS_version_4.0_for_Windows_are_unable_to_restrict_access_for_Cisco_VPN_Clients_that_terminate_on_the_PIX_Firewall" target="_blank"&gt;http://supportwiki.cisco.com/ViewWiki/index.php/Downloadable_ACLs_configured_on_the_Cisco_Secure_ACS_version_4.0_for_Windows_are_unable_to_restrict_access_for_Cisco_VPN_Clients_that_terminate_on_the_PIX_Firewall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will probably get more responses if you post this as a new question (as this thread is marked solved).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Apr 2009 06:45:33 GMT</pubDate>
    <dc:creator>JamesLuther</dc:creator>
    <dc:date>2009-04-09T06:45:33Z</dc:date>
    <item>
      <title>Routing local addresspool for IPsec issue on PIX506E</title>
      <link>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153641#M861146</link>
      <description>&lt;P&gt;My internal networks are 192.168.2.0/24 and 192.168.4.0/24 and are behind a 2811 router. Between 2811 and PIX I use network 10.10.10.8/30. Now I want to use some 192.168.5.0 addresses for a remote access pool, defined on the PIX. When I connect with Cisco VNP client (192.168.5.1) the tunnel comes up but I'm not able to access my internal network. Does anyone know what's wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:15:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153641#M861146</guid>
      <dc:creator>pverstegen</dc:creator>
      <dc:date>2019-03-11T15:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Routing local addresspool for IPsec issue on PIX506E</title>
      <link>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153642#M861147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe a bit obvious, but do you have a route for the 192.168.5.0/24 network on the 2811 router pointing towards the PIX or is this covered by a default route?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you post your config of the PIX and 2811 then it may help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2009 07:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153642#M861147</guid>
      <dc:creator>JamesLuther</dc:creator>
      <dc:date>2009-04-06T07:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Routing local addresspool for IPsec issue on PIX506E</title>
      <link>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153643#M861149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this is covered by the default route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find attached my configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2009 08:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153643#M861149</guid>
      <dc:creator>pverstegen</dc:creator>
      <dc:date>2009-04-06T08:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Routing local addresspool for IPsec issue on PIX506E</title>
      <link>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153644#M861153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps it is to do with NAT?  Try adding the following on the PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp nat-traversal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a new client VPN setup or is it a change to an existing setup?  Have you tried running some debug or packet capture on the PIX to see what is happening?  Are the packets arriving at the PIX in the first place?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2009 09:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153644#M861153</guid>
      <dc:creator>JamesLuther</dc:creator>
      <dc:date>2009-04-06T09:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Routing local addresspool for IPsec issue on PIX506E</title>
      <link>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153645#M861157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, seems that command did the trick. Thanks...&lt;/P&gt;&lt;P&gt;I'm now able to get into the network and reach all machines. The only challenge&lt;/P&gt;&lt;P&gt;there is right now is to get my incoming ACS downloadable ACL working. Maybe you are experienced with this combination: PIX605E 6.3(5) - ACS 4.1(1) Build 23 Patch 5. This is my list:&lt;/P&gt;&lt;P&gt;permit ip host 192.168.4.200 any&lt;/P&gt;&lt;P&gt;deny ip any any&lt;/P&gt;&lt;P&gt;I'm still able to ping other machines in subnet 4 from source address 192.168.5.1&lt;/P&gt;&lt;P&gt;Do you have an idea?&lt;/P&gt;&lt;P&gt;Regards, Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2009 17:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153645#M861157</guid>
      <dc:creator>pverstegen</dc:creator>
      <dc:date>2009-04-08T17:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Routing local addresspool for IPsec issue on PIX506E</title>
      <link>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153646#M861161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the rating.  Sorry I'm not sure about the downloadable ACL.  However I did see this after a quick search&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://supportwiki.cisco.com/ViewWiki/index.php/Downloadable_ACLs_configured_on_the_Cisco_Secure_ACS_version_4.0_for_Windows_are_unable_to_restrict_access_for_Cisco_VPN_Clients_that_terminate_on_the_PIX_Firewall" target="_blank"&gt;http://supportwiki.cisco.com/ViewWiki/index.php/Downloadable_ACLs_configured_on_the_Cisco_Secure_ACS_version_4.0_for_Windows_are_unable_to_restrict_access_for_Cisco_VPN_Clients_that_terminate_on_the_PIX_Firewall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will probably get more responses if you post this as a new question (as this thread is marked solved).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2009 06:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-local-addresspool-for-ipsec-issue-on-pix506e/m-p/1153646#M861161</guid>
      <dc:creator>JamesLuther</dc:creator>
      <dc:date>2009-04-09T06:45:33Z</dc:date>
    </item>
  </channel>
</rss>

