VPN Question

Udgnim

Diamond Member
Apr 16, 2008
3,678
121
106
a VPN connection is being made to a Cisco router with Cisco's VPN client program

access to the 192.168.1.0/24 network is possible through the VPN, but trying to access a different internal network through the VPN is not possible

I'm guessing the reason for this is because the user's default gateway is being used to try to find a route to that different internal network instead of the gateway for the 192.168.1.0/24 network accessed via VPN.

is there a way to change the default gateway to that of the 192.168.1.0/24 network when using the VPN? thanks
 

Qrilock

Member
Dec 20, 2004
101
2
81
The second internal network is either not in the tunneled networks ACL on the router, there is not a proper nat exemption for the second network, or the second network does not have a route to the vpn subnet...
At least those are what I would look for first...
 

Udgnim

Diamond Member
Apr 16, 2008
3,678
121
106
I believe these are settings that the VPN is using

crypto isakmp client configuration group FILLER
key FILLER
dns 192.168.1.1
pool SDM_POOL_1
acl 105
save-password
max-users 10
crypto isakmp profile sdm-ike-profile-1
match identity group FILLER
client authentication list Foxtrot_sdm_easyvpn_xauth_ml_1
isakmp authorization list Foxtrot_sdm_easyvpn_group_ml_1
client configuration address respond
virtual-template 3

I also added the below permit statement to the top of access-list 105

access-list 105 permit ip any any

ip local pool SDM_POOL_1 192.168.1.230 192.168.1.239
ip forward-protocol nd

interface Virtual-Template3 type tunnel
ip unnumbered BVI1
tunnel mode ipsec ipv4
tunnel protection ipsec profile SDM_Profile1

interface BVI1
ip address 192.168.1.254 255.255.255.0
ip nat inside
ip virtual-reassembly

I'm reading that "ip unnumbered" allows an unnumbered interface to borrow the IP address of another interface already configured on the router and that "ip virtual-assembly" is something that helps deal with fragmented traffic being sent through VPN.

Some additional information would be that the 192.168.1.0/24 network represents a network in the office network and the other network I'd like to access through the VPN is on a colocation. The office network is connected to the colo network through a different VPN connection.

After adding the "permit ip any any," I am still unable to access colo network. Thanks for any help.
 

imagoon

Diamond Member
Feb 19, 2003
5,199
0
0
I am pretty sure you are modifying the wrong ACL. Check the split tunnel ACL's etc. You can only access the IP ranges that the VPN ACLs (not interface ACLs) allow.
 

Qrilock

Member
Dec 20, 2004
101
2
81
your ip access list 105 determines what subnets are tunneled across the VPN link. If you wanted 192.168.1.0/24 and 192.168.2.0/24 accessible from your remote access vpn, ACL 105 should look like this:

ip access-list extended 105
permit ip 192.168.1.0 0.0.0.255 any
permit ip 192.168.2.0 0.0.0.255 any

You also need to make sure that NAT is being denied between the two subnets on both the router in your office as well as the router in the COLO.
Since you are trying to traverse 2 VPN tunnels you may want to think about changing the VPN IP pool to something other than your office subnet. I have personally had some periodic issues assigning addresses from my local subnet to VPN clients (probably due to something I am missing, still so much to learn) This will also allow you to remove the virtual template portion of the configuration, simplifying the overall config.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |