<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't access remote computer via VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885932#M957608</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I think we had a network problem after I added inside IP pool or used inside DHCP. Some of computers could not access their Outlook. So, I should use inside IP. right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I add a route command on the PIX to route all VPN traffic to the ASA? If yes, what's the command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jan 2008 01:52:38 GMT</pubDate>
    <dc:creator>chicagotech</dc:creator>
    <dc:date>2008-01-09T01:52:38Z</dc:date>
    <item>
      <title>Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885919#M957595</link>
      <description>&lt;P&gt;We have setup ASA as VPN server. We can establish the VPN, but can't access any remote computers. The configuration can be found here: &lt;A class="jive-link-custom" href="http://www.howtonetworking.com/vista/vistavpn.htm" target="_blank"&gt;http://www.howtonetworking.com/vista/vistavpn.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885919#M957595</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2019-03-11T11:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885920#M957596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't see your config but might be a nat-t problem. Add isakmp nat-traversal or crypto isakmp nat-traversal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2008 14:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885920#M957596</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-05T14:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885921#M957597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry. This is the configuration. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.howtocisco.com/cisco/samples/5510config1.htm" target="_blank"&gt;http://www.howtocisco.com/cisco/samples/5510config1.htm&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you give me step by step details? Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2008 14:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885921#M957597</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-05T14:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885922#M957598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I only see about the last 30 lines of the config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2008 16:29:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885922#M957598</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-05T16:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885923#M957599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I just re-post it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2008 18:16:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885923#M957599</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-05T18:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885924#M957600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;add this command...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp nat-traversal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2008 20:53:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885924#M957600</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-05T20:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885925#M957601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. Will try that Monday and post back with the result.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jan 2008 00:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885925#M957601</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-06T00:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885926#M957602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still doesn't work. From the ASA I can ping inside computer by IP, but can't ping from the VPN client. Any other suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 19:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885926#M957602</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-08T19:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885927#M957603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need these...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list inside_nat0_inbound extended permit ip any 192.168.198.0 255.255.255&lt;/P&gt;&lt;P&gt;.0&lt;/P&gt;&lt;P&gt;no access-list inside_nat0_inbound extended permit tcp 192.168.198.0 255.255.255.0&lt;/P&gt;&lt;P&gt;10.0.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;no nat (inside) 0 access-list inside_nat0_inbound outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 20:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885927#M957603</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-08T20:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885928#M957604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick reply. I took those lines off, but still can't ping. here are part of configuration:&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.x.198 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.0.4 255.255.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.252.254 255.255.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.0.0.0 255.255.0.0 192.168&lt;/P&gt;&lt;P&gt;.198.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list DMZ_nat0_outbound extended permit ip 172.16.0.0 255.255.0.0 192.168.&lt;/P&gt;&lt;P&gt;198.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list test_splitTunnelAcl standard permit any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;ip local pool vpn198 192.168.198.10-192.168.198.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm506.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 10 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 10 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list DMZ_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (DMZ) 10 172.16.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.193 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;group-policy test internal&lt;/P&gt;&lt;P&gt;group-policy test attributes&lt;/P&gt;&lt;P&gt; wins-server value 10.0.0.29 10.0.0.19&lt;/P&gt;&lt;P&gt; dns-server value 10.0.0.29 10.0.0.19&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value test_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value chicagotech.net&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;group-policy CBGVPN198 internal&lt;/P&gt;&lt;P&gt;group-policy CBGVPN198 attributes&lt;/P&gt;&lt;P&gt; wins-server value 10.0.0.29 10.0.0.19&lt;/P&gt;&lt;P&gt; dns-server value 10.0.0.29 10.0.0.19&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelall&lt;/P&gt;&lt;P&gt; default-domain value chicagotech.net&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;group-policy DfltGrpPolicy attributes&lt;/P&gt;&lt;P&gt; banner none&lt;/P&gt;&lt;P&gt; wins-server none&lt;/P&gt;&lt;P&gt; dns-server none&lt;/P&gt;&lt;P&gt; dhcp-network-scope none&lt;/P&gt;&lt;P&gt; vpn-access-hours none&lt;/P&gt;&lt;P&gt; vpn-simultaneous-logins 3&lt;/P&gt;&lt;P&gt; vpn-idle-timeout 30&lt;/P&gt;&lt;P&gt; vpn-session-timeout none&lt;/P&gt;&lt;P&gt; vpn-filter none&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec webvpn&lt;/P&gt;&lt;P&gt; password-storage disable&lt;/P&gt;&lt;P&gt; ip-comp disable&lt;/P&gt;&lt;P&gt; re-xauth disable&lt;/P&gt;&lt;P&gt; group-lock none&lt;/P&gt;&lt;P&gt; pfs disable&lt;/P&gt;&lt;P&gt; ipsec-udp disable&lt;/P&gt;&lt;P&gt; ipsec-udp-port 10000&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value inside_nat0_inbound&lt;/P&gt;&lt;P&gt; default-domain none&lt;/P&gt;&lt;P&gt; split-dns none&lt;/P&gt;&lt;P&gt; secure-unit-authentication disable&lt;/P&gt;&lt;P&gt; user-authentication disable&lt;/P&gt;&lt;P&gt; user-authentication-idle-timeout 30&lt;/P&gt;&lt;P&gt; ip-phone-bypass disable&lt;/P&gt;&lt;P&gt; leap-bypass disable&lt;/P&gt;&lt;P&gt; nem disable&lt;/P&gt;&lt;P&gt; backup-servers keep-client-config&lt;/P&gt;&lt;P&gt; client-firewall none&lt;/P&gt;&lt;P&gt; client-access-rule none&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;  functions url-entry&lt;/P&gt;&lt;P&gt;  port-forward-name value Application Access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; vpn-group-policy CBGVPN198&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 20:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885928#M957604</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-08T20:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885929#M957605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, it work. The problem is all inside computers' default gateway is pointing to a PIX firewall. If I change the computer default gateway to the ASA, the VPN client can ping the computer. We don't have plan to replace the PIX as default gateway. We just want to this ASA as VPN server. How can we configure it so that VPN client access access the LAN resources? Should we make the VPN IP pool to 10.0.0.0/16?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 20:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885929#M957605</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-08T20:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885930#M957606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have an inside router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version is the pix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't want the address pool to be the same as the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All else fails you would have to create persistant routes on your inside hosts to the vpn client subnet. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 21:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885930#M957606</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-08T21:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885931#M957607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also tried to use inside DHCP server to assign IP to the VPN client. The VPN client receives all TCP/IP settings such as IP, DNS, WINS, DHCP server except the default gateway. The default gateway is the VPN client IP. After that, the inside computers can ping the VPN client, but VPN client can't ping the inside computers. Why? Does the VPN client should use itself IP as default gateway? If not, how do you fix it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 21:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885931#M957607</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-08T21:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access remote computer via VPN</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885932#M957608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I think we had a network problem after I added inside IP pool or used inside DHCP. Some of computers could not access their Outlook. So, I should use inside IP. right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I add a route command on the PIX to route all VPN traffic to the ASA? If yes, what's the command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2008 01:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-remote-computer-via-vpn/m-p/885932#M957608</guid>
      <dc:creator>chicagotech</dc:creator>
      <dc:date>2008-01-09T01:52:38Z</dc:date>
    </item>
  </channel>
</rss>

