Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN 3000 Concentrator question - Can get in but can't browse

Status
Not open for further replies.

mdcr

IS-IT--Management
Oct 3, 2001
228
US
We have a VPN that we can connect to from the outside, we get authenticated using the CISCO VPN client v 4.0.1, we can ping machines in the network, but when we try to go to Network Neighborhood or try to map a drive, we can't get anywhere or it will timeout. From certain locations we seem to connect and work fine (usually they don't have a firewall), but this problem mostly occurs at locations that have their own firewall in place. It seems to be related to an outside location's firewall, but the question is, why does this problem allow for a connection to be made, authentication to occur, and then not allow for regular Windows Networking tasks to take place? Any thoughts? Thanks!
 
Have you tried enabling the IPSEC Over TCP feature on your concentrator and VPN client?

On the concentrator, go to Configuration-Systems-Tunneling Protocols-IPSEC-NAT Transparency and enable IPSEC Over TCP, also specifying a port.

On the client, go to Options-Properties and select User IPSEC over TCP, again specifying the port number.

The issue you are seeing has to do with your outside firewalls NATing traffic through an established tunnel. You don't see it when authenticating because all the IKE and IPSEC proposals are still in the process of being built.

In any case, IPSEC over TCP has worked very well for getting around this.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top