03-05-2005 01:53 AM - edited 02-21-2020 01:38 PM
I am tring to connect to vpn server(outside pix) from my laptop inside network.
I have routed the vpn ip on pix515 and pinging fine from pix.but not able to ping from 3550 switch and laptop.
How to route vpn ip on switch ? as i do not know the Mask of the ip....
Also i would like to know ..is their anything extra i have to do on pix or on 3550 switch?
Solved! Go to Solution.
03-06-2005 01:27 PM
Hi!
- What is the default gateway of your laptop?
- Are you doing any type of NAT on the PIX? is it PAT, static or normal NAT?
- Can you ping the inside of the PIX from the laptop?
There could be several problems to fix here.
1) First make sure your laptop has access to the internet
2) If you want to ping the internet make sure you have an ACL on the PIX like the one below:
i.e.
access-list TEST permit icmp any any
access-group TEST in interface outside
Also make sure you have no access-list applied to the inside of the PIX
- Now, can you connect at all?
- Where are you connecting to? another PIX? Router? Concentrator?
If you are going through PAT make sure you have this command on the PIX:
"fixup protocol esp-ike"
Please let me know if you can answer my questions, that way it would be easier to help you.
Frank
03-06-2005 01:27 PM
Hi!
- What is the default gateway of your laptop?
- Are you doing any type of NAT on the PIX? is it PAT, static or normal NAT?
- Can you ping the inside of the PIX from the laptop?
There could be several problems to fix here.
1) First make sure your laptop has access to the internet
2) If you want to ping the internet make sure you have an ACL on the PIX like the one below:
i.e.
access-list TEST permit icmp any any
access-group TEST in interface outside
Also make sure you have no access-list applied to the inside of the PIX
- Now, can you connect at all?
- Where are you connecting to? another PIX? Router? Concentrator?
If you are going through PAT make sure you have this command on the PIX:
"fixup protocol esp-ike"
Please let me know if you can answer my questions, that way it would be easier to help you.
Frank
03-06-2005 11:05 PM
Hi Frank
Thanks for the same ya i am able to ping now i have given icmp any any as u said and it is connecting to concentrator of other end. And if i give icmp any any i am allowing ping request to all will effect any way
Thanks again
Nagalakshmi
03-07-2005 04:58 AM
Good to know that now is working!!!
Dont worry about the ping, if you want you can block it.. There is no need for ICMP to be allowed unless you are using PMTUD, (only on routers).
The trick was the "fixup protocol" which means that on the concentrator side there is no IPSec over TCP/UDP.
Let me tell you that if any other PC tries to VPN to the concentrator, at the same time as your laptop, it will disconnect the first PC. If you want a permanent solution to your problem make sure you configure the concentrator with IPSec over TCP or IPSec over UDP, so you can enable NAT transparency.
The fixup protocol what does is a simple workaround for IPSec through PAT. Remember that PAT breaks IPSec so what the PIX is doing is an encapsulation of ESP packets, for more details please take a look at the link below:
Hope this helps,
Frank
03-07-2005 04:54 AM
Hello,
It's PAT,allowed ICMP.
Yes.I can ping from laptop now.Now i would like to know for vpn outbound connection through dialup, which port should be enabled on pix?Is their any neccessary of fixup ? As i only want to go out of my firwall to connect to partners vpn through ip.
If i am tring to dialup,giving error 721,compture did not respond......
Thanks /Nagalakshmi
03-07-2005 05:25 AM
Hi,
Now you lost me, what do you mean with Dial-Up? Do you mean VPN through a PSTN phone line?
I thought it was working through the PIX... By just adding the fixup protocol on the PIX, any connection through the firewall to a VPN endpoint will work and will "workaround" the PAT problem you have. You can only have one PC doing VPN as explained before.
Please give me more details 'cause I got confused, sorry.
Frank
03-07-2005 09:28 PM
I am Sorry.I mean vpn connection created on laptop.It's going through the pix only.
As i stated earlier i am not able to login to vpn.
What kind of fixup protocol need to open.I tryed "esp-isk" but not getting proper syntex. I am using PIX515 - v6.2.
Even applied acc-list permit for port tcp-1723 and udp-500-isakmp and GRE too.Not sure whether it's required or not.
Regards /Nagalakshmi
03-08-2005 04:40 AM
Ok, let me see...
At this moment I am not sure if you are using PPTP or CISCO VPN CLIENT so we will try both. Make sure you do at least one of the suggestions below:
1) Upgrade to 6.3.4 and issue to following commands:
fixup protocol esp-ike
fixup protocol pptp 1723
2) If you cannot upgrade, then you will need a public IP for your laptop and you will need a static translation for it. If you have one public "free" IP address do this:
static (inside,outside)
access-list VPN permit udp any host
access-list VPN permit udp any eq 500 host
access-list VPN permit esp any host
access-list VPN permit udp any host
access-group VPN in interface outside
That should do the trick. My suggestion is to go for the upgrade, then everything should work if not, please send the configuration. Thanks
Frank
03-30-2005 11:09 PM
HI
Sorry for delay in response. And Thanks a lot for suggestion which you had given we upgraded the FOS to 6.3 version. The VPN connection is working fine now.......added the Fixup protocol pptp 1723 and access list with GRE
Thanks again
Regards
Nagalakshmi
03-31-2005 04:57 AM
You are more than welcome!
Chico
03-30-2005 11:10 PM
HI
Sorry for delay in response. And Thanks a lot for suggestion which you had given we upgraded the FOS to 6.3 version. The VPN connection is working fine now.......added the Fixup protocol pptp 1723 and access list with GRE
Thanks again
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide