republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] Need help getting VPN traffic to access LAN space
Search Topic:
Uniqs:
661
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Assistance with 2 Cisco 2600 Routers via T1 PPP »
« Cisco CME 1760-v : VOIP Provider Question.  
AuthorAll Replies


phantasm11b
Premium
join:2007-11-02
Winter Park, FL


1 edit
[Config] Need help getting VPN traffic to access LAN space

Ok. The VPN works and I can connect but not one is able to access the IP 192.168.1.2. I think I need an IP route statement but am unsure how to route it since the LAN ports are in the BVI. Could someone give me a hand please?


--
"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy


phantasm11b
Premium
join:2007-11-02
Winter Park, FL

Perhaps the issue is with the route map? Maybe I should add a statement permitting the 172.29.100.x access to 192.168.1.2? Hm. I'll try that.
--
"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy


phantasm11b
Premium
join:2007-11-02
Winter Park, FL

reply to phantasm11b
So here's the current state of my outbound_route_map. With this the 192.168.1.1 is accessible but the .1.2 is not.


--
"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy


tubbynet
reminds me of the danse russe
Premium
join:2008-01-16
Chandler, AZ
·Cox HSI
·Callcentric
·Sprint Mobile Broa..
·FrontierNet Intern..

are you split-tunneling the vpn connection or are you tunneling everything?

have you tried adding "include-local-lan" under your crypto group?

if you are denying nat in the route-map by subnet, then you shouldn't need to deny each individual host...

when trying to ping the 1.2 device, are you getting timeouts or replies from a public ip address? have you tried traceing the route to ensure that you are going out the vpn interface and not the public interwebz?

q.
--
"...if I in my north room dance naked, grotesquely before my mirror waving my shirt round my head and singing softly to myself..."


phantasm11b
Premium
join:2007-11-02
Winter Park, FL

I didn't notice your reply until now. Sorry for not responding. Here is where it is at:

Ok. Restarting this thread. I've been working with a member here on the configuration for my router, specifically the VPN. He's been very helpful but with this being a holiday weekend I would not expect him to be online much. As suggested by tubbynet I have not tried adding local-lan to the config. I will try this though.

Problems:
1. When users authenticateon my VPN I see these errors:

»pastebin.com/m657cf2d7


2. Users cannot access LAN assets, particularly 192.168.1.2 (Cisco 2619 – lab router).

3. SSH does not work in either direction. I've disabled the inbound_wan ACL and ssh works. I re-enable it and it does not, however no entries are shown against the ACL when someone tries to connect. The large number of blocked networks have not been an issue until today. SSH worked yesterday, today it does not. What changed? A lot. Lol.

Here's the configuration as it stands.Everything works with the exception of what is mentioned above.


--
"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy


phantasm11b
Premium
join:2007-11-02
Winter Park, FL
SSH is fixed.
-
Forums » Equipment Support » Hardware By Brand » CiscoAssistance with 2 Cisco 2600 Routers via T1 PPP »
« Cisco CME 1760-v : VOIP Provider Question.  


Friday, 27-Nov 21:59:45 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [121] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [68] In-Flight Internet Headed For Bumpy Landing?
· [63] Verizon CEO: Hulu Will Be Dead Soon
· [60] Thanksgiving Open Thread
· [38] EFF Wages War On Fine Print
· [38] ICANN Slams DNS Redirection
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· So we need a legitimate reason to use a lot of bandwidth? [TekSavvy]
· 5 hour energy for diabetic [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· [Scam] Cruise line mail? [Spam, Scam and Phishbusters]