<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Other] Static Route Question in Cisco</title>
<link>http://www.dslreports.com/forum/r22624866</link>
<description></description>
<language>en</language>
<pubDate>Thu, 26 Nov 2009 21:06:15 EDT</pubDate>
<lastBuildDate>Thu, 26 Nov 2009 21:06:15 EDT</lastBuildDate>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22649776</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>Matt</b></A> : <div class="bquote"><small>said by  tubbynet <A HREF="/useremail/u/1520629"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  Matt <A HREF="/useremail/u/843138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</small><br><br>Would you mind sending one as well?<br></div>done and done.  though i would think that you have a little more pull since you've been here longer ;-).<br>i'm just a newcomer.... :D<br><br>q.<br> </div>Eh, that's doubtful. Perhaps the mod didn't think it should have been moved since I was the only one who responded. I appreciate it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22649776</guid>
<pubDate>Fri, 03 Jul 2009 13:16:18 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22649193</link>
<description><![CDATA[<A HREF="/useremail/u/1520629"><b>tubbynet</b></A> : <div class="bquote"><small>said by  Matt <A HREF="/useremail/u/843138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Would you mind sending one as well?<br></div>done and done.  though i would think that you have a little more pull since you've been here longer ;-).<br>i'm just a newcomer.... :D<br><br>q.<br><small>--<br>"...if I in my north room dance naked, grotesquely before my mirror waving my shirt round my head and singing softly to myself..."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22649193</guid>
<pubDate>Fri, 03 Jul 2009 11:08:11 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22649027</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>Matt</b></A> : <div class="bquote"><small>said by  tubbynet <A HREF="/useremail/u/1520629"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>its hard to speculate what is messed up without seeing the config.  this is more appropriate in the cisco forums, however.<br></div>I sent a Hey Mod and asked it to be moved, but it never was. Would you mind sending one as well?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22649027</guid>
<pubDate>Fri, 03 Jul 2009 10:29:16 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22648383</link>
<description><![CDATA[<A HREF="/useremail/u/1520629"><b>tubbynet</b></A> : <div class="bquote"><small>said by  Pluto1914 <A HREF="/useremail/u/954128"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>But I have even tried adding rules to allow bidirectional communication between the two networks on all ports and so far...nothing<br></div>the asa isn't looking for firewall rules to permit traffic.  two things *must* be enabled for proper communication across vpn (aside from the usual connection ike phase i and ii stuff).<br><br>(a) you must allow the subnet to be tunneled across the vpn if you are using a split-tunnel vpn.  if your client isn't made aware of the network (or specific device) then it will never know to pass packets across the vpn interface<br><br>(b) the subnet or host *must* be nat exempt in the access-list referenced by the nat0 statement to the vpn subnet (i.e. if your vpn is connected on 1.1.1.1 and your client is 2.2.2.2, then you must deny nat from 1.1.1.1 to 2.2.2.2, otherwise communication won't work).<br><br>its hard to speculate what is messed up without seeing the config.  this is more appropriate in the cisco forums, however.<br>you may also try googling for the cisco asa configuration guide for your version of the asa-os.  it should have a good reference to get you started on configuring the vpn.<br><br>q.<br><small>--<br>"...if I in my north room dance naked, grotesquely before my mirror waving my shirt round my head and singing softly to myself..."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22648383</guid>
<pubDate>Fri, 03 Jul 2009 02:38:36 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22633119</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>Matt</b></A> : <div class="bquote"><small>said by  Pluto1914 <A HREF="/useremail/u/954128"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>No, as I thought they should.  But I have even tried adding rules to allow bidirectional communication between the two networks on all ports and so far...nothing<br> </div>I don't think a static route is the answer here. It sounds to me like your ASA or the Cisco VPN Client may be misconfigured. Let me see if I can get this moved to the Cisco or Enterprise Admins forum for you.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22633119</guid>
<pubDate>Tue, 30 Jun 2009 10:00:00 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22631292</link>
<description><![CDATA[<A HREF="/useremail/u/954128"><b>Pluto1914</b></A> : No, as I thought they should.  But I have even tried adding rules to allow bidirectional communication between the two networks on all ports and so far...nothing]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22631292</guid>
<pubDate>Mon, 29 Jun 2009 22:01:03 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22631184</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>Matt</b></A> : <div class="bquote"><small>said by  Pluto1914 <A HREF="/useremail/u/954128"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Thats right.  The bosses can be out and about and they want the ability to fire up the VPN and use the AVL client like they are sitting at their desks.<br> </div>Your ASA should take care of the routes for you. When a user connects to the ASA, can they not access the XP machine already?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22631184</guid>
<pubDate>Mon, 29 Jun 2009 21:42:52 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22631098</link>
<description><![CDATA[<A HREF="/useremail/u/954128"><b>Pluto1914</b></A> : Thats right.  The bosses can be out and about and they want the ability to fire up the VPN and use the AVL client like they are sitting at their desks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22631098</guid>
<pubDate>Mon, 29 Jun 2009 21:26:35 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22629350</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>Matt</b></A> : That does clarify. One more thing, when you say you want the VPN users access to "the client," you mean the XP machine correct?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22629350</guid>
<pubDate>Mon, 29 Jun 2009 15:58:57 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22629254</link>
<description><![CDATA[<A HREF="/useremail/u/954128"><b>Pluto1914</b></A> : The Server - Windows XP Pro SP3.  Runs the AVLS server application which receives the location data from the modems and translate that to its mapping software for tracking.<br><br>The VPN connection is handled via the Cisco ASA Firewall<br><br>There are three networks involved in this setup.<br><br>The VZW network with the DUN Modem.<br>The work LAN where the server sits.<br>Finally the VPN network which has full access to the LAN for the server.<br><br>I hope this helps.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22629254</guid>
<pubDate>Mon, 29 Jun 2009 15:41:21 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22625897</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>Matt</b></A> : Unfortunately, your post isn't very clear, so we'll need some more information.<br><br>First, what is the "server?" What OS? What does it do?<br><br>Secondly, what is handling your VPN connectivity? <br><br>Thirdly, if I understand your post correctly, it looks like you have a "work" network and some "other" network. The VPN connects to the "other" network. Does the "work" network and the "other" network have any sort of physical connectivity?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22625897</guid>
<pubDate>Sun, 28 Jun 2009 22:00:52 EDT</pubDate>
</item>

<item>
<title>[Other] Static Route Question</title>
<link>http://www.dslreports.com/forum/remark,22624866</link>
<description><![CDATA[<A HREF="/useremail/u/954128"><b>Pluto1914</b></A> : We use AVL software at work.  The server has an airlink modem on the verizon wireless network connected via a serial cable.  Connectivity is made via a DUN connection.  The server is also on works network so that admin's can use teh client software in house.  We also use a VPN connection that allows admins access to network resources.  The VPN is is a seoerate network form the LAN and through the firewall ist is allowed through.<br><br>I am trying to allow the users on the VPN connection access to the client.  Unfortunately they cannot run the software.  So I think if I put a route statement on the sever I should be able to rectify this.  I just need help in establishing what the statement should be.<br><br>Any ideas?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22624866</guid>
<pubDate>Sun, 28 Jun 2009 17:51:20 EDT</pubDate>
</item>

</channel>
</rss>
