<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pix 501 vpn problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303202#M949917</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Success, I couldn't believe it. It was an enjoyable experience. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made only one change that I can see by comparing the config files;  I removed a specific computer that was in the list of internal networks. &lt;/P&gt;&lt;P&gt;The lines were:&lt;/P&gt;&lt;P&gt;pdm location x.x.x.x 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;http x.x.x x. 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm have no idea if this did it or not. Maybe the problem was that it was in the same subnet as the main http network?  I can test later. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't had the same luck with the mac os x vpn client.  I can connect and get an ip from the vpn pool but can't ping or find the internal networks.  I checked the the routes logged in the mac using netstat but I don't see the ip given by the pix to  the mac.    If it is connected it must have the route, or at least it seems it should.  Maybe this behavior by netstat is normal for a vpn connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was going to work on this later today after other tasks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help and patience in walking me through this.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Aug 2009 16:42:57 GMT</pubDate>
    <dc:creator>verstand76</dc:creator>
    <dc:date>2009-08-17T16:42:57Z</dc:date>
    <item>
      <title>pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303186#M949898</link>
      <description>&lt;P&gt;I can connect but don't see any network resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Vpn Client, ver:5.0.01, is running on an xp machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network it is connecting to is behind a pix501- Ver. 6.3(5).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the connection is made the remote client gets an assigned address from the vpn pool 192.168.2.10- 192.168.2.25:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The vpn client log shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Line:45     18:07:27.898  08/12/09  Sev=Info/4	CM/0x63100034&lt;/P&gt;&lt;P&gt;The Virtual Adapter was enabled: &lt;/P&gt;&lt;P&gt;	IP=192.168.2.10/255.255.255.0&lt;/P&gt;&lt;P&gt;	DNS=0.0.0.0,0.0.0.0&lt;/P&gt;&lt;P&gt;	WINS=0.0.0.0,0.0.0.0&lt;/P&gt;&lt;P&gt;	Domain=&lt;/P&gt;&lt;P&gt;	Split DNS Names=&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is followed by these lines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;46     18:07:27.968  08/12/09  Sev=Warning/2	CVPND/0xE3400013&lt;/P&gt;&lt;P&gt;AddRoute failed to add a route: code 87&lt;/P&gt;&lt;P&gt;	Destination	192.168.1.255&lt;/P&gt;&lt;P&gt;	Netmask	255.255.255.255&lt;/P&gt;&lt;P&gt;	Gateway	192.168.2.1&lt;/P&gt;&lt;P&gt;	Interface	192.168.2.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;47     18:07:27.968  08/12/09  Sev=Warning/2	CM/0xA3100024&lt;/P&gt;&lt;P&gt;Unable to add route. Network: c0a801ff, Netmask: ffffffff, Interface: c0a8020a, Gateway: c0a80201.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;48     18:07:28.178  08/12/09  Sev=Info/4	CM/0x63100038&lt;/P&gt;&lt;P&gt;Successfully saved route changes to file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;49     18:07:28.198  08/12/09  Sev=Info/6	CM/0x63100036&lt;/P&gt;&lt;P&gt;The routing table was updated for the Virtual Adapter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;50     18:07:29.760  08/12/09  Sev=Info/4	CM/0x6310001A&lt;/P&gt;&lt;P&gt;One secure connection established&lt;/P&gt;&lt;P&gt;* ...&lt;/P&gt;&lt;P&gt;I can ping, from the remote client, to an inside ip behind the pix even&lt;/P&gt;&lt;P&gt;when I get the "add route failure" shown above,  but i can't ping the computer name.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I enabled NAT traversal using the PDM,  But when I connect with this option I get the error that the "Remote end is NOT behind a NAT device This end IS behind a NAT device" and ping fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Behind the pix are a few computers with no central server so I'm not passing a WINS server to the remote client. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set up the vpn with the wizard. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the config file.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hugh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303186#M949898</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2020-02-21T11:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303187#M949900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Add to your config NAT-T  and try again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)#isakmp nat-traversal &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#Solution1" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#Solution1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 18:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303187#M949900</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-13T18:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303188#M949902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did try : isakmp nat-traversal but got the error I noted in my post. I even couldn't ping then. I'll try again.  Do I need to add any seconds or just leave blank? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 18:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303188#M949902</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-13T18:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303189#M949904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you correct your vpn pool to be consistant with your nonat exempt rule prior to troubleshooting fruther.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have /28 pool network, that gives 14 hosts  and range should start at host .1 to .14 , your config have &lt;B&gt;ip local pool vpp1 192.168.2.10-192.168.2.25&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your vpn pool shoudl be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool vpp1 192.168.2.1-192.168.2.14&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as for the NAT-T  the 20 is default so automatically will be added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[edit]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after you correct vpn pool network range try vpn client and access resources in the 192.168.1.0/24 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post results &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 19:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303189#M949904</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-13T19:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303190#M949905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, I'll will change the pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just tried the nat-t but still nothing to "see".  I was able to ping inside though, so I must of had some other config setting when ping failed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm still getting the "add route failure" in the client log;  is this significant?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the client log shows connected and continues with line after line of &lt;/P&gt;&lt;P&gt;"Sent a keepalive on the IPSec SA"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll post new results after pool change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 19:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303190#M949905</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-13T19:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303191#M949906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hugh, correct the pool first and try again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 19:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303191#M949906</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-13T19:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303192#M949907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, i'm on my way to try the new pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 19:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303192#M949907</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-13T19:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303193#M949908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I changed the pool.  Still can't see computer behind pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ipconfig shows for cisco adapter an ip of 192.168.2.1  but has no default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Route Details window: Local LAN routes is empty and Secured routes has 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bytes sent and received show some in the client statistics but if i check the cisco vpn network via network connections it shows 0 bytes sent and received. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VDP port 4500 and says local lan disabled ;  i don't understand this as I have 'allow local lan access' checked in the client set up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm still getting the "add route failure"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 20:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303193#M949908</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-13T20:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303194#M949909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hugh,  ok you corrected the vpn pool, looking at the config  seems  to be ok  split tunnle alcl etc.. which makes me think perhaps vpn client itself or machine, have you tried different version of vpn client , or even from a different machine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;post again an updated config for a second look .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;     &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 01:10:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303194#M949909</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-14T01:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303195#M949910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I've tried client ver. 4.9.61 on a Mac OS X 10.5.7;  it connects but I see nothing, nor can I ping.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have cisco vpn client 5.0.00.0340 which I can try from windows. What do you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The windows os I've tried so far is xp home service pack 2 with cisco client 5.0.01 as noted in first post. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can try from another windows os xp home service pack 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attached is latest config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for working on this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hugh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 13:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303195#M949910</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-14T13:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303196#M949911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry..I did not notice  the crypto acl is incorrect , change it to be  /28, you have it with a /27.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove this:&lt;/P&gt;&lt;P&gt;no access-list outside_cryptomap_dyn_20 permit ip any 192.168.2.0 255.255.255.224 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;replace with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit ip any 192.168.2.0 255.255.255.224 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_20 permit ip any 192.168.2.0 255.255.255.240 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;post if still issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 15:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303196#M949911</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-14T15:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303197#M949912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, i need to get this clear:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you mean replace the line:&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_20 permit ip any 192.168.2.0 255.255.255.224&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with this line:&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_20 permit ip any 192.168.2.0 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 17:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303197#M949912</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-14T17:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303198#M949913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Hugh,  I placed the no in the line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;no&lt;/B&gt; access-list outside_cryptomap_dyn_20 permit ip any 192.168.2.0 255.255.255.224 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and add to your config &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_20 permit ip any 192.168.2.0 255.255.255.240 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we just need to make config clear and consistant  to rule out vpn config discrepancies in your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 18:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303198#M949913</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-14T18:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303199#M949914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, I see that the 'no' is part of the command.  It did remove the line. I'm about to test now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed in viewing configuration settings through the PDM that under VPN/IPSec Rules in the Remote Side panel (detail view) should both  be 192.168.2.0/28 ?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After I changed access-list outside using the command line tool, this panel had 192.168.2.0/28 but below it was 192.168.2.0/27.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed this /27 via Edit and saved. an error message came up but it now shows both as 192.168.2.0/28.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I presume this is correct. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 18:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303199#M949914</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-14T18:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303200#M949915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, try testing again..  after that crypto acl correction at least the vpn config is consistant and narrow down troubleshooting effort.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make also sure that hosts behind the PIX the 192.168.1.0 network don't have any firewalls turned on so that vpn pool network can ping  those hosts by ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 19:30:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303200#M949915</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-14T19:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303201#M949916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hugh, whats the progress on your issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2009 16:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303201#M949916</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-17T16:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303202#M949917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Success, I couldn't believe it. It was an enjoyable experience. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made only one change that I can see by comparing the config files;  I removed a specific computer that was in the list of internal networks. &lt;/P&gt;&lt;P&gt;The lines were:&lt;/P&gt;&lt;P&gt;pdm location x.x.x.x 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;http x.x.x x. 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm have no idea if this did it or not. Maybe the problem was that it was in the same subnet as the main http network?  I can test later. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't had the same luck with the mac os x vpn client.  I can connect and get an ip from the vpn pool but can't ping or find the internal networks.  I checked the the routes logged in the mac using netstat but I don't see the ip given by the pix to  the mac.    If it is connected it must have the route, or at least it seems it should.  Maybe this behavior by netstat is normal for a vpn connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was going to work on this later today after other tasks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help and patience in walking me through this.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2009 16:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303202#M949917</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-17T16:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303203#M949918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I forgot to mention that even when I connected successfully via windows vpn client, I still got the "addRoute failed to add." ( error code 87 in the vpn client log) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2009 16:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303203#M949918</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-17T16:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303204#M949919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hugh, post an updated config again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say success, then you still get the same error code, what is it ? is it working or not? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case PLS post config once again to see where we are, also add to  your config prior posting these two statement for testing the access to PIX inside interface IP from RA VPN client. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(config)#management-access inside &lt;/P&gt;&lt;P&gt;(config)#telnet 192.168.2.0 255.255.255.240 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2009 18:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303204#M949919</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-08-17T18:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: pix 501 vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303205#M949920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll have to get back to you later with the config and then I can do the changes as suggested.  Right now i'm pressed by the usual flood of 'sudden' monday deadlines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, I thought I was clear.  I can connect and view shared resources via the windows os vpn client.  This is what i was unable to do before. while connected I then checked the vpn client log to see if the 'addRoute' error was there and it was. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I concluded that this error was not critical for the problem of viewing the network ( prior to this I had searched the web using "cisco error code 87" and found someone who had a network viewing problem but had solved it and they too still had the "addroute" error. Unfortunately they didn't explain how they solved their problem) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so 'success' meant: yes I can connect and view network resources; but for some reason 'addroute' error still happens&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly: I can connect with the mac vpn client but I can't ping internal network nor can i view shared resources behind the pix501. ( both of which I can now do from the windows client)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my line of thought here is it has to do with the mac os X system but I haven't had time to research it yet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what's your idea behind the testing plan?&lt;/P&gt;&lt;P&gt;Is this something I would monitor from inside the pix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hugh &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2009 19:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-vpn-problem/m-p/1303205#M949920</guid>
      <dc:creator>verstand76</dc:creator>
      <dc:date>2009-08-17T19:41:40Z</dc:date>
    </item>
  </channel>
</rss>

