05-07-2004 11:57 PM - edited 02-21-2020 01:08 PM
Scenario: Two companies both behind PIX firewalls. Company A uses the Cisco VPN client to connect to the Company B network from a single PC (behind the Company A firewall). This works and the client can access the necessary servers. Company A also has mobile clients that use Cisco VPN client connections from home to connect to its own (Company A) network which they can do successfully.
Company B is trying to use the Cisco VPN client to connect to the Company A network from a single PC (behind Company B firewall). Company B manages to connect to the network succesfully, but it unable to access any resources and cannot ping any destinations on the Company A network.
I have tested the VPN client configuration Company B was given using a dial up Internet link with no problems.
Any ideas why this problem might be occuring?
Many thanks
Mark
05-09-2004 08:11 AM
is company b filtering outgoing traffic?
05-10-2004 09:53 AM
Make sure Company A's PIX is running software version 6.3 and add the "isakmp nat-traversal" command. If this doesn't work, then try to create a static translation for the PC behind Company B, on company B's PIX, so that the VPN client can connect using a non-PATted IP address.
05-13-2004 05:52 AM
Also make sure you have
sysopt connection permit-ipsec
on the other pix as it is probably already on pixA
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide