cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
466
Views
0
Helpful
2
Replies

IPN Not Passing Traffic

AJ Cruz
Level 3
Level 3

I deployed an IPN to do posture assessments on VPN users. Right now I have no posture checks enabled and I have authorization happening with a "permit all" DACL, but I cannot pass traffic (no ping from VPN client to an internal resource).

For the heck of it I put a subnet filter for my VPN pool on the IPN and then I get ping, so that makes me think routing is all good, must be the IPN right?

Any ideas?

Thanks!

1 Accepted Solution

Accepted Solutions

Tarik Admani
VIP Alumni
VIP Alumni

From the ipn can you issue a "show pep session table"? You should see the client ip address. If jot check the tunnel group to see if the accounting server group and the authentication server group points to the ipn node. Also make sure you are hitting the inline node authorization profile.


Sent from Cisco Technical Support Android App

View solution in original post

2 Replies 2

Tarik Admani
VIP Alumni
VIP Alumni

From the ipn can you issue a "show pep session table"? You should see the client ip address. If jot check the tunnel group to see if the accounting server group and the authentication server group points to the ipn node. Also make sure you are hitting the inline node authorization profile.


Sent from Cisco Technical Support Android App

That was it, the accounting command was missing on the firewall. Thanks.