08-03-2004 07:53 PM
Hi,
I have a PIX 515 v6.3(3) and I've vpngroup configured for the users to connect using the Cisco VPN client. Once the users are connected to the VPN, they are not able to access any subnet other than the locally connected subnet on ot the Inside interface of the PIX.The inside interface is connected to a Catalyst 6509 layer 3 with 14 VLANs configured on it.
I have tried with and without split-tunnel.
Any lifelines ???
Thanks
Jins Varghese
08-04-2004 05:25 AM
Does the routing logic on the Catalyst know how to forward to the address pool in the PIX?
HTH
Rick
08-04-2004 07:58 PM
Hi Rick,
All the routes were perfect. Infact, I got a incidental workaround and am banging my head on to PIX as I cannot understand the logic behind this. I was able to ping the VPNed client from all the internal subnets all the time.
The workaround : Once the user is connected thru the VPN, ping the user IP (Provided by the VPN pool) and the inside interface of the PIX from the internal server to which the user need to connect. Once this is done the user will be able to connect to that particular server from which pinged the PIX and client. For each server user needs to be connected, I need to do the Ping......
Weired... !!!!
Looks like some ARP issues. Am gonna clear all the ARP entries on Cayalysts and PIX.
Any thoughts ??
Thanks
Jins
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide