cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
571
Views
0
Helpful
2
Replies

VPN 3002 behind cable modem

v-yelmene
Level 1
Level 1

I have experienced something odd with our 3002 Hardware Clients behind a Cable Modem. It appears that if the Client does not have a current session established with the Concentrator, we are unable to communicate with the 'public' interface on the Client. The 'public' interface IP is provided by the ISP, and statically assigned. The Clients also have a default gateway entry pointing to the ISP gateway.

I figured the public interface would still be accessable even if no IPSEC session is established with the Concentrator.

Does anyone know why this would happen?

2 Replies 2

travis-dennis_2
Level 7
Level 7

First off is the public interface reachable when an IPSec session is up? You have to allow http(s) access on the public interface by rules on the 3002. Also are you allowing split tunneling? If not then this may pose a problem depending on your configuration as the only traffic allowed to pass would be through the tunnel (that does not exist).

Hope this helps.

Please remember to rate all replies

Yes, the public is reachable when IPSEC session is up.

https is enabled on public interface.

Split tunneling is also enabled.

Review Cisco Networking for a $25 gift card