<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Config] VPN issues in Cisco</title>
<link>http://www.dslreports.com/forum/r20421061</link>
<description></description>
<language>en</language>
<pubDate>Thu, 04 Dec 2008 16:05:56 EDT</pubDate>
<lastBuildDate>Thu, 04 Dec 2008 16:05:56 EDT</lastBuildDate>

<item>
<title>Re: [Config] VPN issues</title>
<link>http://www.dslreports.com/forum/remark,20424220</link>
<description><![CDATA[<A HREF="/useremail/u/1072934"><b>DocLarge</b></A> : Leathal,<br><br>every forum you go to, it's the same s**t, dude.  You have a problem you can't figure out, then you criticize the folks who can't fix the problem you came looking for help with.  The lacking of intelligence isn't within this forum, moreso, the person asking for help...<br><br>A majority of us in this forum are Cisco certified, and I can think of a few people who "could" help you but most likely won't bother now because they are "intelligent" enough (by reading your commentary) not deal with your attitude.<br><br>Oh, as TomS would say, "looks like you've got homework!"  :)<br><br>Jay]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20424220</guid>
<pubDate>Fri, 02 May 2008 23:54:25 EDT</pubDate>
</item>

<item>
<title>Re: [Config] VPN issues</title>
<link>http://www.dslreports.com/forum/remark,20423839</link>
<description><![CDATA[<A HREF="/useremail/u/1387340"><b>elnino</b></A> : Like I said before, in my experience, it has never been a problem with our Cisco PIX or VPN Concentrator, it was always a problem with the connection at the client's home.  In some cases, the cable modems themselves had firewalls built in that were also blocking ports.<br><br>Let's try some troubleshooting questions.... Is it always the same people that have problems with VPN?  Have you "problem" laptops from a known "good" internet connection?  Are they plugging into home routers or directly into the cable modem?  Do they have firewalls active and if so, what ports are open?  Are IPSec (protocol 50), UDP 500, UDP 4500 and UDP 10000 open on your users' home routers/firewalls?<br><br>-Brandon]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20423839</guid>
<pubDate>Fri, 02 May 2008 22:19:37 EDT</pubDate>
</item>

<item>
<title>Re: [Config] VPN issues</title>
<link>http://www.dslreports.com/forum/remark,20422981</link>
<description><![CDATA[<A HREF="/useremail/u/1520629"><b>tubbynet</b></A> : Just a friendly reminder:<br><br>These forums are NOT tech support.  It is a support community where volunteers come together to paruse and solve problems.  It is NOT assistance whenever you need it.  If someone can help you, they will try their best.   elnino <A HREF="/useremail/u/1387340"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> gave you an answer that solved his problem based on his experience.  There is no reason to insult him.<br><br>If you needed it immediately, you could have called TAC as soon as the problem manifested itself.  There is a lot of "intelligence" here, we just aren't paid to provide support to end users.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20422981</guid>
<pubDate>Fri, 02 May 2008 19:06:26 EDT</pubDate>
</item>

<item>
<title>Re: [Config] VPN issues</title>
<link>http://www.dslreports.com/forum/remark,20422907</link>
<description><![CDATA[<A HREF="/useremail/u/581584"><b>Leathal</b></A> : <div class="bquote"><small>said by  elnino <A HREF="/useremail/u/1387340"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Generally speaking, the problem is either with their home router or ISP.  The home router isn't IPSEC passthru compatible or isn't passing NAT-T.  I get a call like this every couple months.  I go back and check the logs and on our VPN Concentrator there is no traffic received but there is traffic sent.  Normally when I have them plug directly into their cable modem, it works. Once behind their router, it stops working.<br> </div>I guess we'll have to phone Cisco and speak to someone with some intelligence as it's obvious I came to the wrong place again... (sigh)<br><br>Leathal]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20422907</guid>
<pubDate>Fri, 02 May 2008 18:50:31 EDT</pubDate>
</item>

<item>
<title>Re: [Config] VPN issues</title>
<link>http://www.dslreports.com/forum/remark,20422367</link>
<description><![CDATA[<A HREF="/useremail/u/1387340"><b>elnino</b></A> : Generally speaking, the problem is either with their home router or ISP.  The home router isn't IPSEC passthru compatible or isn't passing NAT-T.  I get a call like this every couple months.  I go back and check the logs and on our VPN Concentrator there is no traffic received but there is traffic sent.  Normally when I have them plug directly into their cable modem, it works. Once behind their router, it stops working.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20422367</guid>
<pubDate>Fri, 02 May 2008 16:51:06 EDT</pubDate>
</item>

<item>
<title>Re: [Config] VPN issues</title>
<link>http://www.dslreports.com/forum/remark,20421834</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : <div class="bquote"><small>said by  Leathal <A HREF="/useremail/u/581584"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>We have not been able to figure out how to make the VPN stable and have thought about putting something like Checkpoint or ISA server to replace the VPN.  </div>Replace PIX with other product like Checkpoint or ISA may not solve the problem, without understanding thoroughly the problem cause.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20421834</guid>
<pubDate>Fri, 02 May 2008 15:01:38 EDT</pubDate>
</item>

<item>
<title>[Config] VPN issues</title>
<link>http://www.dslreports.com/forum/remark,20421061</link>
<description><![CDATA[<A HREF="/useremail/u/581584"><b>Leathal</b></A> : We have PIX 515e's UR/FO<br><br>We use "vpnclient-win-msi-5.0.02.0090-k9.exe" on the clients.<br><br>When we login from different internet providers, the ones at the office or ones at peoples homes 50% of them the PIX conneds to the LAN and the 50% of the time it doesn't. So in the statistics info you see everything normally except the Packets Decrypted is 0, and the bytes recieved is also 0, but sent byes are counting up, and ther rest of the packets are moving up as well. <br><br>Here is a copy of the config. We have not been able to figure out how to make the VPN stable and have thought about putting something like Checkpoint or ISA server to replace the VPN. If you see anything wrong with the config that would effect the VPN please let me know... Thanks.<br><br>timeout xlate 3:00:00<br>timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02<br>timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00<br>timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00<br>timeout uauth 0:05:00 absolute<br>dynamic-access-policy-record DfltAccessPolicy<br>no snmp-server location<br>no snmp-server contact<br>snmp-server enable traps snmp authentication linkup linkdown coldstart<br>crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac<br>crypto dynamic-map OUTSIDE_DYN_MAP 20 set transform-set ESP-3DES-MD5<br>crypto map OUTSIDE_MAP 30 match address S2SVPN<br>crypto map OUTSIDE_MAP 30 set peer <br>crypto map OUTSIDE_MAP 30 set transform-set ESP-3DES-MD5<br>crypto map OUTSIDE_MAP 65535 ipsec-isakmp dynamic OUTSIDE_DYN_MAP<br>crypto map OUTSIDE_MAP interface outside<br>crypto isakmp identity address<br>crypto isakmp enable outside<br>crypto isakmp policy 10<br> authentication pre-share<br> encryption 3des<br> hash md5<br> group 2<br> lifetime 86400<br>crypto isakmp policy 20<br> authentication pre-share<br> encryption des<br> hash md5<br> group 1<br> lifetime 86400<br>crypto isakmp policy 65535<br> authentication pre-share<br> encryption 3des<br> hash sha<br> group 2<br> lifetime 86400<br>no crypto isakmp nat-traversal<br>telnet 192.168.75.0 255.255.255.0 inside<br>telnet timeout 5<br>ssh 0.0.0.0 0.0.0.0 outside<br>ssh 192.168.75.0 255.255.255.0 inside<br>ssh timeout 30<br>ssh version 1<br>console timeout 0<br>threat-detection basic-threat<br>threat-detection statistics access-list<br>group-policy clientgroup internal<br>group-policy clientgroup attributes<br> dns-server value 192.168.75.2 192.168.75.15<br> vpn-idle-timeout 20<br> password-storage enable<br> default-domain value fcproduction.local<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>username password encrypted privilege 15<br>username password encrypted<br>username password encrypted<br>username password encrypted<br>tunnel-group Users2VPN type remote-access<br>tunnel-group Users2VPN general-attributes<br> address-pool ippool1<br> default-group-policy clientgroup<br>tunnel-group Users2VPN ipsec-attributes<br> pre-shared-key *<br>tunnel-group 208.124.189.155 type ipsec-l2l<br>tunnel-group 208.124.189.155 ipsec-attributes<br> pre-shared-key *<br>!<br>class-map class_ftp<br> match port tcp eq ftp-data<br>class-map inspection_default<br> match default-inspection-traffic<br>!<br>!<br>policy-map type inspect dns preset_dns_map<br> parameters<br>  message-length maximum 512<br>policy-map global_policy<br> class inspection_default<br>  inspect dns preset_dns_map<br>  inspect h323 h225<br>  inspect h323 ras<br>  inspect netbios<br>  inspect rsh<br>  inspect rtsp<br>  inspect skinny<br>  inspect sqlnet<br>  inspect sunrpc<br>  inspect tftp<br>  inspect sip<br>  inspect xdmcp<br>  inspect ftp<br>  inspect esmtp<br>!<br>service-policy global_policy global<br>prompt hostname context<br>Cryptochecksum:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20421061</guid>
<pubDate>Fri, 02 May 2008 12:18:42 EDT</pubDate>
</item>

</channel>
</rss>
