12-01-2003 12:12 AM
Hi,
I have PIX firewall with statefull failover.
I have configured PIX for VPN client 3.0. The user is getting authenticated by the RADIUS server. But I am unable to ping to the inside network. (This is directly connected subnet.) I have checked all routes as well.
Can anybody suggest why the VPN client workstation is not able to ping the inside network ?
Regards,
Sunil
12-01-2003 12:21 AM
Hi,
Did you write the acl to permit that traffic?By default, PIX doesn't permit any traffic from outside or DMZ to inside. Can you send your configuration?
12-01-2003 12:37 AM
Yes the acl is in place.
Regards,
Sunil
12-01-2003 12:48 AM
Did you permit the vpn client's ip address in acl or did you use downloadable acl from radius? or maybe icmp is not permitted in your acl, (which I did the same mistake before ;)..
12-01-2003 01:34 AM
Yes I have permitted the vpn clients ip address in acl. ICMP and IP are permitted.
One more thing....once I get connected I see transport tunneling : "Inactive" in the VPN client connection status.
01-14-2004 02:23 AM
Sunilyk, Did you ever manage to get this working ? I have the exact same problem - the config looks OK and the client authenticates and gets allocated an address but then cannot connect. Any help would be much appreciated
01-14-2004 03:14 AM
Hi -
Have got: nat (inside) 0 access-list
Thanks -
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide