frank298
Posts: 1
Joined: 31.May2007
Status: offline
|
HI everyboby, I am connecting from home to my job network using Cisco vpn client terminated in a Pix with IOS 6.3. Everything is ok but I can't use firewall client as I usually do when I am connected in my office. In fact there is an ISA Server 2000 beyond the Pix and I can go to Internet through the proxy configured in Internet Explorer from home but when I try to enable the firewall client I get the following: "isa server xxx is inaccessible" and after some minutes the vpn goes down. Looking in the ISA logs I saw the following lines: 192.168.123.224, SYSTEM, cvpnd.exe:3:5.1, -, 5/31/2007, 12:09:19, -, WEB, -, -, xx.xx.xxx.xx, 4500, 995000, 0, 0, 4500, UDP, UdpMap, -, -, -, 20000, -, -, -, 60, 1227 192.168.123.224, SYSTEM, cvpnd.exe:3:5.1, -, 5/31/2007, 12:09:19, -, WEB, -, -, -, 0, 995047, 0, 0, 0, UDP, Bind, -, -, -, 20001, -, -, -, 60, 1227 In the LAT there was the range 192.168.0.1-192.168.32.255, comprehensive of all the network router toghether in mpls company network. I added a LAT entry for 192.168.123.0-192.168.123.255 that is the network pool used by Pix to lease the vpn adapter addresses. I have read that is possible to define explicit policies to permit vpn traffic through the ISA ( udp 500, 4500 and 10000) but it seemed to me the it was necessary connecting from inside job network to an external network and anyway I didn't understand very much about. Anybody help? Thanks Franco
|