My VPN doesn't work.!!!

Hi All,
I configured a sample VPN in a 2611 Router to connect via Cisco VPN Client Sfw from a Remote PC on internet.
When the tunnel is estabilished, all networks stop to work in my PC.
I can't access the LAN inside.
Could anybody help me to solve this problem ?
Follow my config :
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service linenumber
hostname mtech_lab_rt1
boot-start-marker
boot-end-marker
enable password xxx
no network-clock-participate slot 1
no network-clock-participate wic 0
aaa new-model
aaa authentication login LOCALUSERS local
aaa session-id common
ip subnet-zero
ip domain name xxx.com
ip cef
ip audit po max-events 100
username dticsco password 0 xxx
ip ssh time-out 60
ip ssh authentication-retries 2
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp client configuration group HOME
key xxx
dns 192.168.0.4
domain xxx.com
pool CLIENT_ADDRESSES
crypto ipsec transform-set MTECHVPN_SET esp-3des esp-sha-hmac
crypto dynamic-map CLIENT_MAP 1
set transform-set MTECHVPN_SET
reverse-route
crypto map MTECHVPN_VPN client authentication list LOCALUSERS
crypto map MTECHVPN_VPN isakmp authorization list LOCALUSERS
crypto map MTECHVPN_VPN client configuration address respond
crypto map MTECHVPN_VPN 100 ipsec-isakmp dynamic CLIENT_MAP
interface FastEthernet0/0
ip address 192.168.0.130 255.255.255.0
ip nat inside
duplex auto
speed auto
interface FastEthernet0/1
ip address 41.x.x.15 255.255.254.0
ip nat outside
duplex auto
speed auto
crypto map MTECHVPN_VPN
ip local pool CLIENT_ADDRESSES 192.168.2.1 192.168.2.10
ip nat inside source list NATLIST interface FastEthernet0/1 overload
ip nat inside source static tcp 192.168.0.6 25 41.x.x.15 25 extendable
ip nat inside source static tcp 192.168.0.6 110 41.X.X.15 110 extendable
ip http server
no ip http secure-server
ip classless
ip route 0.0.0.0 0.0.0.0 41.x.x.1
ip route 192.168.0.0 255.255.255.0 FastEthernet0/0
ip access-list standard NATLIST
permit 192.168.0.0 0.0.0.255
dial-peer cor custom
line con 0
location work
exec-timeout 30 30
password cisco
line aux 0
password cisco
line vty 0 4
login authentication LOCALUSERS
transport input ssh
end
Thanks
AB

version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service linenumber
hostname mtech_lab_rt1
boot-start-marker
boot-end-marker
enable password MtechP@zz11E
no network-clock-participate slot 1
no network-clock-participate wic 0
aaa new-model
aaa authentication login USERAUTHEN local
aaa authorization network GROUPAUTHOR local
aaa session-id common
ip subnet-zero
ip domain name mydomain.com
ip cef
ip audit po max-events 100
username antonio password 0 tonhao01
username dticsco password 0 dt!czc0
username ricardo password 0 ric123
username belarmino password 0 bneves0511
ip ssh time-out 60
ip ssh authentication-retries 2
crypto isakmp policy 3
encr 3des
authentication pre-share
group 2
crypto isakmp client configuration group MTECHVPN
key Mdt@Vpn!zz030459
dns 192.168.0.4
wins 192.168.0.4
domain mydomain.com
pool ippool
acl 101
crypto ipsec transform-set myset esp-3des esp-md5-hmac
crypto dynamic-map dynmap 10
set transform-set myset
reverse-route
crypto map clientmap client authentication list USERAUTHEN
crypto map clientmap isakmp authorization list GROUPAUTHOR
crypto map clientmap client configuration address respond
crypto map clientmap 10 ipsec-isakmp dynamic dynmap
interface FastEthernet0/0
ip address 192.168.0.130 255.255.255.0
ip nat inside
duplex auto
speed auto
interface FastEthernet0/1
ip address 41.x.x.15 255.255.254.0
ip nat outside
duplex auto
speed auto
crypto map clientmap
ip local pool ippool 10.1.1.10 10.1.1.20
ip nat inside source list 111 interface FastEthernet0/1 overload
ip http server
no ip http secure-server
ip classless
ip route 0.0.0.0 0.0.0.0 41.x.x.1
access-list 101 permit ip 192.168.0.0 0.0.0.255 10.1.1.0 0.0.0.255
access-list 111 deny ip 192.168.0.0 0.0.0.255 10.1.1.0 0.0.0.255
access-list 111 permit ip any any
dial-peer cor custom
line con 0
location work
exec-timeout 30 30
password 7 02050D480809
line aux 0
password 7 0822455D0A16
line vty 0 4
login authentication USERAUTHEN
transport input ssh
end

Similar Messages

  • VPN doesn't work

    I just switched from Cable Internet to Verizon high speed.  Internet and e-mail work fine, but my Cisco VPN doesn't work with Verizon.
     Thus I can't connect to my servers at work.
    I know my VPN works good because I travel alot and it works in every hotel I stay at, in fact I just tried it down the street through WiFi.
    Does anyone know the fix for this?

    Easy solution......
    Bridge mode is achieved by 2 easy steps:
    1) - Log into the GUI
    click the My Network Icon on top
    Click Network Connections on the left
    Click on the words "Broadband Connection (DSL)"
    Make the Protocol dropdown say "Bridge"
    Make the Bridge Mode dropdown say "Bridge"
    Save - the unit will reset
    2) Log back into the GUI
    Click the My Network icon on top
    Click Network Connections on the left
    Click the on the word "LAN"
    Remove the top checkmark (you want to not enable the DHCP Server)
    Make sure the modems ip address is not going to be the same of your router
    Save
    Exit the GUI
    I made my modem 192.168.10.1, and my routers lan network is 192.168.0.1
    The 6100F is bridged. The internet light will stay out. Whatever the next device on the network is will need to do the PPPoE connection (with your ISP username and password) ex your router
    Myk

  • My VPN doesn't work ever since I upgraded to iOS7

    My VPN doesn't work ever since I upgraded to iOS7, pls help?

    It's been a problem with ios 7, for now try using your apple id for it. Apple is supposed to be putting out a fix for it soon.

  • VPN doesn't work anymore after 10.6.2 update

    Hello to all,
    I've a MacPro with 10.6 SnowLeopard server, and until yesterday all was great with 10.6.1.
    After update to 10.6.2 plus some airport update, VPN dooesn't work.
    Could someone help me?
    I use the firewall on Airport extreme (the latest model) and automatically forward VPn setting from SLServer Firewall.
    Why it don't go anymore?
    thank you to all for help
    Marco
    Italy

    so, I'm trying from home to use VPN:
    - if I try from usual user, doesn't work
    - if I try from Server Administrator credentials (user + password) it works
    Of course I need to use VPN from "normal" client users, not with Administrator credentials
    Another strange issue is: in VPN netwotk configaration (client, preferences, network) if I put name and password about one user the 2 field become locked and I must erase that VPN connection and create it again.
    If I put the administrator name+psw, the 2 field remaining accesible and unlocked.
    I think in Apple they made a very bad job with 10.6.2 and VPN!
    has someone any suggestion?
    Marco

  • VPN doesn't work since I reset permissions

    Hi .
    Recently I reset my permissions via disk utility app, Since I did that, VPN doesn't connect on my mac. it works with same VPN information on my iPad & iPhone so the problem is not from VPN.
    I'll be glad if you could help me.

    Try:
    - Reset the iOS device. Nothing will be lost
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Reset all settings      
    Go to Settings > General > Reset and tap Reset All Settings.
    All your preferences and settings are reset. Information (such as contacts and calendars) and media (such as songs and videos) aren’t affected.
    - Restore from backup. See:                                 
    iOS: How to back up                                                                
    - Restore to factory settings/new iOS device.             
    If still problem, make an appointment at the Genius Bar of an Apple store since it appears you have a hardware problem. Other users have had the same problem.
    Apple Retail Store - Genius Bar                                      

  • PPTP VPN doesn't work on iOS 6

    I just tried to set up my iPad 2 (on iOS6) for an already working PPTP VPN server on my DD-WRT and found out that it doesn't work anymore (apparently somethings changed after iOS 4.3 according to tons of blogs on the net) There seems to be a few solutions about adding a couple entries to /tmp/pptpd/options.pptpd but none of these worked for me on iOS 6. Is there anyone knows a solution to this problem?
    Note: nopcomp, noaccomp, default-asyncmap, mru 1400, mtu 1400 options do not work nor doesn't seem to help a bit at all, by looking at the dd-wrt log output. Most people claim these options make it work for iOS 5, but didn't work for me.

    Yeah, resurrecting old thread here...
    I was having similar problems with iOS6 and my DDWRT running on Buffalo WZR-600DHP.  After I changed the mtu & mru to 1400, it worked.  It was driving me nuts before.

  • Changed the Shared Secret, and now VPN doesn't work...

    Hello all. So our VPN was working fine. I changed the Shared Secret, and it stopped working. Seems like any Shared Secret now that I use doesn't work, and I've been triple-checking it on both the server and clients to make certain that it's not miss-typed.
    It seems to connect OK, but then it fails to authorize. I've got the proper ports open, and again, it worked just fine with the first Shared Secret I used.
    Is there something I'm missing about Shared Secrets here? You should be able to change them when you need too, right?
    Message was edited by: Jeffrey McGrew

    Looking at the logs I'm seeing something strange that I don't understand. It appears that one part of the authorization is succeeding, and another part failing:
    "DSAuth plugin: Could not authenticate key agent for encryption key retrieval."
    Then, two lines later:
    "CHAP peer authentication succeeded for USER"
    "DSAccessControl plugin: User 'USER' authorized for access"
    But then the client never shows that it's authorized. So is this a problem with the client configuration, since the server is showing an authorized session starting, or is there something wrong with the DSAuth Plugin?
    (going to read more PDFs)

  • Client VPN doesn't work until reload; all other services are fine

    We have a 1800 router running 12.4.x that is acting up.  Every week or 2, client vpn connectivity stops working on it (clients receive a ' reason 412; the remote peer is no longer responding' when trying to connect).  All other traffic running through that router continues to work fine (site to site, nat, etc).  If we run a 'clear ip nat translation', then ONE client can reconnect, but any subsequent clients cannot.  So, basically one at a time.  the only 'fix' is a reboot of the router.  any suggestions on where to start troubleshooting?
    thanks!                  

    Matt,
    Did you disable NAT-T on this device?
    http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#solution01
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • Connection to VPN doesn't work with exclamation mark on Network symbol

    Hello everyone,
    I'm new to this forum and not really professional in VPN stuff, though I'm an experienced computer user and programmer. I'm using Cisco VPN
    5.0.07.0440-k9-x64 from the Paul Scherrer Institute on Windows 8 64-bit. The program was working previously fine, but at some point, whenever I connect to VPN and login, I lose connection to the internet, and nothing related to my internet connection work, and I see an exclamation mark on the wireless network symbol. And when I disconnect the VPN, I get everything back to normal.
    I got almost the same problem when I installed Kaspersky Internet Security due to some suspicion on security, but then I removed it and everything was back to normal. After that, the VPN worked for some time, and again didn't work anymore at some point. First thing I tried is disabling the Windows Firewall, and it didn't help.
    My network adapter is: Qualcomm Atheros AR9002WB-1NG Wireless Network Adapter
    In my network adapter, I can't change the TCP/IP v4 Configuration. When I double click, it says something like: "For the configuration of TCP/IP, there must be a network device installed and activated" (The sentence is translated from German, my Windows is German).
    Is there like a "global reset" that would get the VPN to work again? What should I do?
    Please advise, and if you require any piece of information, let me know.
    Thank you.

    I'm using now VPNC on linux. No more cisco! Crappy program and crappy support!

  • VPN doesn,t work on WRT54GX-v2 either

    Hi, I have exactly the same problem with my WRT54GX-v2 as other people had with there WRT54G v6 http://forums.linksys.com/linksys/board/message?board.id=Wireless_Routers&message.id=183
    A new version seem to fix the problem, but I can't fine any update to my GX-version.
    Have anyone succeed to have VPN working on WRT54GX model ?

    hi , if you are facing issues with you VPN ,make sure that the "VPN passthrough" is enabled under the security page of the router.Access the setup using http://192.168.1.1 and enable VPN passthrough if disabled..
    If this does not work you have have to forward the following ports on the router . 1723,500,50,43-47,445 .
    On how to forward ports visit this link http://kb.linksys.com and look for answer ID 688

  • VPN doesn't work at build 10049

    VPN has worked at previous builds but not anymore at build 10049.
    When I choose VPN-network provider whole Settings-windows shuts down.

    Hi fiantsirk,
    There have been some known issues in Windows 10 build 10049:
    No access to Internet Protocol (v4 or v6) in 10049
    VPN configurations might be affected, folks here have found out some ways to make it work (3rd-party software related), you may check at :
    https://social.technet.microsoft.com/Forums/en-US/261392a2-3914-4518-acb4-065a0a635f58/build-10049-breaks-openvpn-there-are-no-tapwindows-adapters-on-this-system?forum=WinPreview2014General
    Best regards
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Leopard - now VPN doesn't work anymore..

    Hello everyone,
    Yesterday i installed Leopard on my Macbook.
    VPN didn't seem to work after the install so I downloaded Cisco VPN Client 4.9.01 (0080). At first, everything seemed to work but now, when i connect to VPN my internet connection does not work anymore. VPN stays connected but both safari and camino fail to open any website..
    Can anyone help me please? I really need to finish my essays and for this I really need VPN..!!!
    Thank you!

    Hi
    I had the same problems with Tiger and the CISCO VPN Client. One minute it would work, the next it wouldn't. Nothing I did would make it work. I kept getting an error. With some digging about I found the following article:
    http://cb1inc.com/2007/06/11/fixing-cisco-vpn-client-4.9-with-parallels-desktop- 3.0-on-mac-os-x
    OK, haven't installed Leopard (waiting for it to appear in Christmas presents!) so not sure this will solve your problem, but there might be people out there who have a similar problem and the above link might solve it. Also not sure how this relates to Parallels as the CISCO client worked long after I installed Parallels. It seemed to be after an Update to Mac OS X the that VPN stopped working.
    OK. I'm going on a bit now!
    Good luck!

  • Re: VPN doesn't work on my new Portege Z830

    I recently bought a portege z830. I installed watchguard firebox vpn connection software but i can not establish a vpn connection. I enter the username and password, the program seems to make a connection but it disconnects immediately. There's no problem with the password or username.
    The software works fine in other notebooks. The OS on the machine is Windows 7 Prof.(X64).
    Thanks

    I really dont know if described issue has anything directly with your new Portege. I presume you need this for your business or you must use it in your company so I strongly recommend you to speak with your local administrator and check what can be done about it.
    On this virtual way it is not easy to say what is wrong there. On my Satellite P500 I use Cisco AnyConnect VPN client and it works perfectly with preinstalled original Toshiba recovery image. It is Win7 64bit Home Premium.

  • L2TP VPN doesn't work (IVPN software as server)

    Hello,
    I am having problems to setting up VPN connection from win XP to my MBP (WAN connection).
    I use IVPN sofware on my MBP as VPN server config software. All my software and firmware are up to date.
    All the right ports are mapped in my AEBS (means 1701, 1723, 4500 and 500).
    When I try my VPN connection from LAN to LAN it works fine (L2TP and PPTP).
    When I try from WAN it is not working at all.
    The win XP things says : "error 678 : no response" or sometimes "timed out".
    My WAN Ip is static, my LAN IP's too.
    I've tryed the DMZ (default host) workaroud, but still no results.
    Does the AEBS really VPN passthrought? Cause some forums says it's not...
    Please help.
    A very old mac user (since 24 years).
    Thanks.
    Phil.

    shinzonqc wrote:
    I've tryed the DMZ (default host) workaroud, but still no results.
    Does the AEBS really VPN passthrought? Cause some forums says it's not...
    I do not believe the AEBS completely supports passthrough traffic (even though it's supposed to). The thread over here: http://discussions.apple.com/thread.jspa?messageID=4046689 would seem to indicate that many people are having problems with VPN.

  • Incoming VPN doesn't work with PAT over DHCP

    I have an 1841 that uses PAT for outbound traffic.  External Fe0/0 port gets its IP via DHCP. 
    ip nat inside source route-map NAT-MAP interface FastEthernet0/0 overload
    I have an internal server that runs SSH so I have a port forwarding rule on the router:
    ip nat inside source static tcp 172.16.32.3 22 interface FastEthernet0/0 22
    Now I added VPN pool, but VPN clients cannot reach the server on port 22. 
    The statement below would fix the problem:
    ip nat inside source static tcp 172.16.32.3 22 <STATIC IP> 22 route-map NO_NAT-MAP extendable
    If I understand correctly this statement is only available for STATIC IPs, in my case I get the IP from DHCP.  Anyone knows a workaround?
    thanks!

    Resolved!
    It appears that he Scientific Atlantic modem than RCN provides needs a hard reset when switching routers. The way to do this is a careful sequence:
    1. unplug ethernet to old router
    2. unplug coax
    3. power off for at least 60 seconds
    4. plug in coax
    5. power up and check for status lights
    6. plug ethernet cable between the Time Capsule and the modem
    This time it picked up the DHCP settings and hence works just fine. Phew! So, the problem was not with Apple but with RCN.
    Jonathan

Maybe you are looking for

  • JBO-26080 error during commit

    Hi, I am getting a JBO-26080 error attempting to commit a view using the Business component browser. The error is: (oracle.jbo.DMLException) JBO-26080: Error while selecting entity for Bank The view, entity and stack trace are below. Any insight appr

  • How do I tell how much hard drive space I have left?

    I have an iMac v. 10.5.8 and want to know how to check how much hard drive space I have left. Thank you!

  • QT does not open AVI file

    hello, I have installed Perian but with Mountain Lion QT does not open AVI file (no audio and no video) do you have any suggestion?

  • How to detect conversion errors due to charset mismatch client/server?

    If a character cannot be converted by OCIStmtExecute (Bind Variable) and/or OCIStmtFetch (Into Variable), either a replacement character (usually question mark) or a similar character (e.g. è -> e) is used instead. I am looking for a possibility to g

  • Change the Account Name?

    i tried to change my account name. however after i changed it .. i still could see the old name in the finder.. but when i log on i see the new account name.. how can i fix this