cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
879
Views
5
Helpful
2
Replies

connected VPN users can't access any resources

1salvarez
Level 1
Level 1

User is able to connect, get's assigned an IP, we can see them connected
via ASDM, they can't access anything in our network.

1 Accepted Solution

Accepted Solutions

Hi,


Check the following:

When attempting to send traffic check the output of ''sh cry ips sa'' to make sure packets encrypted/decrypted increments.

If not...

Could be that NAT-T is not configured.

Check the configuration for:

crypto isakmp nat-t

sh run all sysopt--> should show sysopt connection permit-vpn

Test:

Add the command

management-access inside

And try to PING the inside IP of the ASA from the VPN client.

Let's take it from here...

Federico.

View solution in original post

2 Replies 2

Hi,


Check the following:

When attempting to send traffic check the output of ''sh cry ips sa'' to make sure packets encrypted/decrypted increments.

If not...

Could be that NAT-T is not configured.

Check the configuration for:

crypto isakmp nat-t

sh run all sysopt--> should show sysopt connection permit-vpn

Test:

Add the command

management-access inside

And try to PING the inside IP of the ASA from the VPN client.

Let's take it from here...

Federico.

someone made a change which affected the users. Below are his remarks:

I added crypto map 10 for connectivity to site1 and the crypto map ACL that I added for that tunnel to match was too broad in scope and included all 192.168.0.0/16 networks.  Will get more specific on the allowed traffic for that tunnel.

Thanx for your help Federico.