cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
457
Views
0
Helpful
2
Replies

VPN Client to secondary internal network

dianad
Level 1
Level 1

I have a VPN client setup that works great for my internal network. But I need them to be able to access a secondary internal network, which currently they can't do. I can ping the devices fine from the PIX (meaning the routes and return routes are working fine), but the VPN clients cannot when they are connected. I have added that secondary network to the access-list the VPN clients are using. Is this possible, and if so, what might I be missing?

2 Replies 2

mike-greene
Level 4
Level 4

Hi,

Can you post your PIX config? Also can you do a sh access-list and see if your getting hit's on the new ACL line. Are you using split tunneling? When you ping from the PIX your sourcing from the PIX interface IP address. This is probably not the IP range your giving your VPN clients when they connect. If there is another router involved beyond the PIX, if you do a sh ip route on your VPN client subnet does it route it correctly?

Hope that helps with troubleshooting.

Hey, thanks for the response. I have since found the problem. I didn't have the access-list for the NAT 0 command in there. Once I put that in, everything was working great. Soooo close, yet soooo far!