Re: Cico 800 (836) VPN to Internet NAT
- From: Daniel-G <free-news_no-replyATcasylde.fr>
- Date: Mon, 12 May 2008 10:43:07 +0200
Merv a écrit :
On May 11, 3:41 pm, HangaS <mafo...@xxxxxxxxx> wrote:I posted this early in the morning :Hi,
I've been struglin for this for a long while.
I've done tons of searches and haven't found a solution on how to
solve this.
Even read all the Cisco documentation on VPDNs, but no help on this
particular issue.
This is my issue:
I have this cisco 836 providing NAT for all the internal networks.
Everything working fine.
I also have a VPN that is working normaly for the internal networks
only. A client connected
to the VPN can access the internal network without problems.
However the VPN users can't access the internet and I have no ideia
where the packets are being droped.
I realy wanted the VPN network to be NATed to the outside, just like
any other internal network.
take a look at this Cisco doc
Router and VPN Client for Public Internet on a Stick Configuration
Example
http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration_example09186a008073b06b.shtml
HangaS a écrit :
> Hi Merv,
>
> I have come across this doc before, but found others that introduce me
> to split-tunneling.
>
> I didn't want to use a crypto-map neither to use the Cisco VPN client.
> I wanted to use the default Windows client in a next-next-finish
> config maner.
>
> Anyway I tryed to adapt the solution from this doc to my setup. I had
> tryed a similar one before with the loopback interface for the split
> tunnel, but the route-map had a set ip next-hop instead of a set
> interface.
>
> I did some troubleshooting and I fhat the packets are being
> NATed to the internet, reach the target host which sends a reply back
> to the outside IP address of my router but seems that the reply is not
> being traslated back to the VPN network. (altough there is an entry
> for in the 'show ip nat translation' list.
>
> Now I just read in some forum while looking for 'vpdn split tunnel'
> that I can't use split tunniling with pptp? is this true?
>
>
>
>
> On May 11, 9:38 pm, Merv <merv.hr...@xxxxxxxxxx> wrote:
>
>> take a look at this Cisco doc
>>
>> Router and VPN Client for Public Internet on a Stick Configuration
>> Example
>>
>> http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_config...- Hide quoted text -
>>
>> - Show quoted text -
>
Split tunneling can't be set with pptp as it is the responsability of
the vpn client to manage access w/wo a policy pushed by the routeur
(tunnel end point on branch side)
You have to manage static routes on the client side, as with pptp the
default gw alwaysdefaults to the pptp address (make a route print on
your client)
I hab a batch to modify it. I'll try to find quickly and post it here
Hope this helps
Daniel
.
- Follow-Ups:
- Re: Cico 800 (836) VPN to Internet NAT
- From: HangaS
- Re: Cico 800 (836) VPN to Internet NAT
- References:
- Cico 800 (836) VPN to Internet NAT
- From: HangaS
- Re: Cico 800 (836) VPN to Internet NAT
- From: Merv
- Cico 800 (836) VPN to Internet NAT
- Prev by Date: Re: Cico 800 (836) VPN to Internet NAT
- Next by Date: Re: catalyst3560 and citrix sessions problem
- Previous by thread: Re: Cico 800 (836) VPN to Internet NAT
- Next by thread: Re: Cico 800 (836) VPN to Internet NAT
- Index(es):
Relevant Pages
|
Loading