cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1195
Views
0
Helpful
4
Replies

VPN only partially working...

mtehonica
Level 5
Level 5

I configured a VPN on my ASA5505 and it seems to be working just fine if I connect with my iPad or iPhone.  But if I use the Cisco VPN Client, I can authenticate but can't get to any other the server that I can access just fine from my iPad.  I can RDP from my iPad to servers but I can't RDP from my laptop to the same servers.  Any ideas what would cause this??

4 Replies 4

mtehonica
Level 5
Level 5

Bump.  Any ideas on this.  I tested a bit more and all clients can connect and function fine except the Cisco VPN Client on Windows.  iPad/iPhone/Mac Built in Cisco IPsec VPN work fine.  The client on Windows shows traffic being sent through the tunnel but nothing recieved....

Can you try it from another Windows machine using the same .PCF file?

Seems like there has to be something wrong with your client config if it works from everywhere else.

dt

Yeah, I've tried on 2 different computers at 2 different locations.  Both machines were Windows 7.  I just can't seem to figure out what would be causing this.  I can see traffic going through the tunnel to the ASA, for example from my logs....

6May 11 201213:12:18
10.0.0.1263990172.16.20.103389Built inbound TCP connection 89945 for backupisp:10.0.0.12/63990 (10.0.0.12/63990) to insidemgmt:172.16.20.10/3389 (172.16.20.10/3389) (matt)

And I can connect to this same machine fine using the VPN client on the iOS devices and the Mac laptop.

Here is a route print from my laptop while connected to the VPN client...

C:\Users\Matt>route print

===========================================================================

Interface List

32...00 05 9a 3c 78 00 ......Cisco Systems VPN Adapter for 64-bit Windows

13...1c 65 9d e8 ea e6 ......DW1501 Wireless-N WLAN Half-Mini Card

  1...........................Software Loopback Interface 1

12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface

46...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #4

19...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6

===========================================================================

IPv4 Route Table

===========================================================================

Active Routes:

Network Destination        Netmask          Gateway       Interface  Metric

          0.0.0.0          0.0.0.0     172.16.1.254     172.16.1.127     25

         10.0.0.0    255.255.255.0         On-link         10.0.0.12    281

         10.0.0.0    255.255.255.0         10.0.0.1        10.0.0.12    100

        10.0.0.12  255.255.255.255         On-link         10.0.0.12    281

       10.0.0.255  255.255.255.255         On-link         10.0.0.12    281

       10.40.40.0    255.255.255.0         10.0.0.1        10.0.0.12    100

        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306

        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306

  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306

       172.16.1.0    255.255.255.0         On-link      172.16.1.127    281

     172.16.1.127  255.255.255.255         On-link      172.16.1.127    281

     172.16.1.254  255.255.255.255         On-link      172.16.1.127    100

     172.16.1.255  255.255.255.255         On-link      172.16.1.127    281

       172.16.2.0    255.255.255.0         10.0.0.1        10.0.0.12    100

      172.16.20.0    255.255.255.0         10.0.0.1        10.0.0.12    100

  208.125.237.118  255.255.255.255     172.16.1.254     172.16.1.127    100

        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306

        224.0.0.0        240.0.0.0         On-link      172.16.1.127    281

        224.0.0.0        240.0.0.0         On-link         10.0.0.12    281

  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306

  255.255.255.255  255.255.255.255         On-link      172.16.1.127    281

  255.255.255.255  255.255.255.255         On-link         10.0.0.12    281

===========================================================================

Persistent Routes:

  None

IPv6 Route Table

===========================================================================

Active Routes:

If Metric Network Destination      Gateway

12     58 ::/0                     On-link

  1    306 ::1/128                  On-link

12     58 2001::/32                On-link

12    306 2001:0:4137:9e76:1499:3b10:53ef:fe80/128

                                    On-link

12    306 fe80::/64                On-link

12    306 fe80::1499:3b10:53ef:fe80/128

                                    On-link

  1    306 ff00::/8                 On-link

12    306 ff00::/8                 On-link

===========================================================================

Persistent Routes:

  None

I have the same issue with some Windows 7 and the problem is the metric of the route that vpn client add, is metric 100.

When your default gw lan/wlan metric is 25, with vpn connected and metric 100... is not possible work.

I'm still working how to solve this problem.