cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
376
Views
0
Helpful
1
Replies

Can ping but no web access

admin_2
Level 3
Level 3

Hi,

I am stumped by this strange issue.

We are trying to setup a VPN for remote access using VPN 3005. Clients connecting from outside the campus can bring up a tunnel. Since we are doing split tunneling, they can access the Internet. Also, they can access the campus webpage, library page and email server. All these are in the same VLAN as the inside interface of the VPN concentrator. However, servers that reside on other VLANs cannot be accessed. I thought that addresses assigned by the concentrator might be getting blocked by our inside router. So, I a defined an access list saying allow everything from the clients address (did this only for one VLAN). Now, I can ping a server in that VLAN but I still cannot access webpages from there.

I find this very strange, why is TCP traffic getting blocked? Any thoughts? Thanks for the help.

Vipul

1 Reply 1

Not applicable

Hi,

Some more informationa about the problem. I sniffed the data and I see that when TCP traffic is being sent, there is an exchange of ISAKMP informational message. This is not seen when sending ICMP only.

Thanks.

Vipul