<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with VPN Client in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899523#M959856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;add the following in respective order&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;object-group network Clients&lt;/P&gt;&lt;P&gt;network-object 172.16.2.1 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.2 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.3 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.4 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.5 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.6 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.7 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.8 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.9 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.10 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.11 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.12 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.13 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.14 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.15 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.16 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.17 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.18 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.19 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.20 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.21 255.255.255.255&lt;/P&gt;&lt;P&gt;q&lt;/P&gt;&lt;P&gt;access-list no_nat permit ip 10.0.0.0 255.255.255.0  object-group Clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that, client will be able to reach inside network, but they will lose their local connectivity. To avoid this, add the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list split_T permit ip 10.0.0.0 255.255.255.0 object-group Clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpngroup nikas split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas1 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas2 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas3 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas4 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas5 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas6 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas7 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas8 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas9 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas10 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas11 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas12 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas13 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas14 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas15 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas16 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas17 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas18 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas19 split-tunnel split_T&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Nov 2007 12:12:17 GMT</pubDate>
    <dc:creator>Alan Huseyin Kayahan</dc:creator>
    <dc:date>2007-11-28T12:12:17Z</dc:date>
    <item>
      <title>Problem with VPN Client</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899520#M959853</link>
      <description>&lt;P&gt;Hello everyone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please give me some help with the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to connect with a VPN Client which is behind a Checkpoint F/W to a CiscoPIX 515. Although the connection is established i cannot access the internal network behind the PIX. I configured NAT-T in PIX 515 and open the appropriate tcp/udp ports (500,4500,10000) in chekpoint but i get the following error in the log file of the VPN Client:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Systems VPN Client Version 5.0.00.0340&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Copyright (C) 1998-2006 Cisco Systems, Inc. All Rights Reserved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client Type(s): Windows, WinNT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running on: 5.1.2600 Service Pack 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;45     16:15:56.593  11/27/07  Sev=Warning/2      CVPND/0xA3400011&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error -14 sending packet. Dst Addr: 0xFFFFFFFF, Src Addr: 0xC0A8003B (DRVIFACE:1201).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;46     16:15:59.312  11/27/07  Sev=Warning/2      CVPND/0xA3400015&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error with call to IpHlpApi.DLL: DeleteIpForwardEntry, error 87&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;47     16:15:59.312  11/27/07  Sev=Warning/2      CM/0xA3100025&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unable to delete route. Network: c0a800ff, Netmask: ffffffff, Interface: a000096, Gateway: c0a8003b.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;48     16:15:59.312  11/27/07  Sev=Warning/2      CVPND/0xA3400015&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error with call to IpHlpApi.DLL: DeleteIpForwardEntry, error 87&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;49     16:15:59.312  11/27/07  Sev=Warning/2      CM/0xA3100025&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unable to delete route. Network: c0a80000, Netmask: ffffff00, Interface: a000096, Gateway: c0a8003b.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899520#M959853</guid>
      <dc:creator>otenet_cass</dc:creator>
      <dc:date>2019-03-11T11:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN Client</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899521#M959854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please post your PIX config, most probably it is a tunneling issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2007 09:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899521#M959854</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-11-28T09:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN Client</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899522#M959855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply. Please find attached the PIX config file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2007 09:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899522#M959855</guid>
      <dc:creator>otenet_cass</dc:creator>
      <dc:date>2007-11-28T09:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN Client</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899523#M959856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;add the following in respective order&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;object-group network Clients&lt;/P&gt;&lt;P&gt;network-object 172.16.2.1 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.2 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.3 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.4 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.5 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.6 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.7 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.8 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.9 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.10 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.11 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.12 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.13 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.14 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.15 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.16 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.17 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.18 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.19 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.20 255.255.255.255&lt;/P&gt;&lt;P&gt;network-object 172.16.2.21 255.255.255.255&lt;/P&gt;&lt;P&gt;q&lt;/P&gt;&lt;P&gt;access-list no_nat permit ip 10.0.0.0 255.255.255.0  object-group Clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that, client will be able to reach inside network, but they will lose their local connectivity. To avoid this, add the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list split_T permit ip 10.0.0.0 255.255.255.0 object-group Clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpngroup nikas split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas1 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas2 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas3 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas4 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas5 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas6 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas7 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas8 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas9 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas10 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas11 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas12 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas13 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas14 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas15 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas16 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas17 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas18 split-tunnel split_T&lt;/P&gt;&lt;P&gt;vpngroup nikas19 split-tunnel split_T&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2007 12:12:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-vpn-client/m-p/899523#M959856</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-11-28T12:12:17Z</dc:date>
    </item>
  </channel>
</rss>

