07-13-2009 08:58 AM - edited 03-11-2019 08:54 AM
I have a PIX 501 with an active L2L tunnel on it. I have also just added a remote access vpn, in which I'll be connecting to the inside network with the Cisco vpn client using local authentication. I've got it setup so I can authenticate and get an assigned ip address, but I cannot ping across to the inside network anywhere. I have sysopt enabled so that is not the issue. I'm not sure if something is conflicting with the L2L tunnel or not. I've attached the config and broken it up to best describe what its doing. Can someone please advise on to what the issue could be?
07-13-2009 10:15 AM
Add...
isakmp nat-traversal
07-13-2009 10:25 AM
That did it!!
Can you explain why that is needed? Appreciate the fix!
07-13-2009 02:45 PM
Hi
During the phase II negotiation there is seperate unidirectional ESP session between PIX and the VPN client.So when there is NAT involved in the set up there are issues due to the translation .
To overcome those issues NAT-T is used.
http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1732264
HTH
Ullas
07-13-2009 03:29 PM
That's where I'm confused. I'm not NATn'g anything.
07-14-2009 05:54 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide