cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
411
Views
0
Helpful
1
Replies

gfb: cannot browse a Windows domain with VPN Client 3000

adm
Level 1
Level 1

Hi there,

Can someone please give me some pointers? I've set up a pix 515 6.0(1) (only 56 bit des license) to accept dynamic vpn connections from VPN 3000 clients. In addition, clients will be authenticated by a TACACS+ server. I'm convinced I've set up the config correctly to support this, and the users connect to the tunnel correctly and authenticate against the TACACS+ server perfectly, however... it seems as if the access list I set up for the dial-up vpn users does not take effect and when users try to access windows domain servers, the firewall explicitly drops these requests, and I see 106011: errors.

Has anyone got any ideas?

Kind Regards,

Gabriel

1 Reply 1

k.poplitz
Level 3
Level 3

Make sure you are using a WINS server for netbios name resolution. The broadcast browse-mastering will not work (reliably) over a vpn tunnel.