02-08-2010 07:26 AM
Good Day,
In Cisco PIX RA VPN, recently i have expanded the ip pool from 172.16.x.x/24 to 172.16.x.x/23 and changed the corresponding access-list and nat entries, after which few of the users reported that they were unable to connect internet and other internal resources.
kindly advice.
Regards,
SSOC Support
02-08-2010 08:33 AM
When changing this scope, did you made sure that it did not overlap with any alreadya allocated network segment like the inside network?
02-08-2010 09:01 AM
Yeah, i'm sure that it doesn't overlap anywhere.
but more frequent the problem occurs only for the users at specified location and not for all the locations
02-08-2010 09:31 AM
You might need to enable split-tunnel on the PIX to allow VPN Clients access to the Internet while they are tunneled in.
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080702999.shtml
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide