09-24-2004 06:18 PM
I can't get traffic through the router that my PIX is directly connected to. I'm using vpngroups with LOCAL authenication. I can successfully ping the 2611 router interface directly beneath my PIX, and I can also ping any device sharing the same subnet as that interace, but I can't ping any other interface on the router. Other traffic from the PIX passes normally. There are no ACLs preventing access from the VPN client pool from leaving the 2611. Am I missing something? If I do a traceroute from a VPN client the traffic times out once it pings the leading interface on the 2611.
09-24-2004 06:19 PM
Sorry, I should have specified "VPN" traffic.
09-26-2004 06:09 PM
Are there any other routers in your network besides the 2611?
Examine the router config with regards to route statements, and protocols, as well as route-maps and nat/pat configuration. Are you doing nat/pat on the 2611 for any type of traffic, such as non-vpn traffic, but using a route-map to bypass nat/pat for vpn traffic? Are you using static routes on the 2611?
Please run the debug ip packet on the 2611, and then have the vpn client send a packet thru it, and post the debug results here.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide