07-13-2012 04:26 AM - edited 02-21-2020 06:11 PM
Hi Guys,
I'm trying to connect our ipads to vpn to access lan resources. The cisco ipad ipsec connects though no lan access and cannot ping anything not even interfaces on the router.
If i setup the cisco vpn on a laptop it works perfectly i can ping everything and can access resources on the lan so my guess is traffic is not going down the vpn tunnel between ipad and office.
cisco 877.
Attached is my config.
Any ideas ?
Thanks
Solved! Go to Solution.
07-13-2012 05:26 AM
The build-in iPad-client is not campatible with your setup.
You have three options:
1) remove the acl from your vpn-group. Without split-tunneling the client will work.
2) migrate back to the legacy config style with crypto-map. There you can use split-tunneling
3) migrate to AnyConnect.
The background of the problem is, that the iPad receives the split-tunneling-information. But instead of controlling with routing which traffic should go throuh the tunnel and which traffic is allowed without the VPN, the iPad tries to build one set of SAs for each line in your split-tunnel-ACLs. But with the virtual-template only one SA is allowed.
07-13-2012 05:26 AM
The build-in iPad-client is not campatible with your setup.
You have three options:
1) remove the acl from your vpn-group. Without split-tunneling the client will work.
2) migrate back to the legacy config style with crypto-map. There you can use split-tunneling
3) migrate to AnyConnect.
The background of the problem is, that the iPad receives the split-tunneling-information. But instead of controlling with routing which traffic should go throuh the tunnel and which traffic is allowed without the VPN, the iPad tries to build one set of SAs for each line in your split-tunnel-ACLs. But with the virtual-template only one SA is allowed.
07-13-2012 06:53 AM
I see. Seems bit strange as i have another line with almost identical vpn set and i can ping and access lan on that vpn. What your saying makes sense i'll try removing acl from vpn group tonight.
Thanks
07-13-2012 07:27 AM
it depends on the order of your ACEs. With a little luck all your needed traffic was matched against the first ACE in your ACL.
Sent from Cisco Technical Support iPad App
07-14-2012 08:40 AM
Thank you i've been struggling for 3 days with this your explanation was spot on.
Thanks again
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide