VPN: one is working, the other is not...

I have several interfaces:
outside
inside(192.168.0.0/24)
wifi(192.168.101.0/24)
haklab(10.10.10.0/24)
Currently I have remote access anyconnect users who are able to VPN in and get access to the outside internet and inside devices.
I am trying to add another VPN config to allow users to connect to the haklab resources from the outside. 
Currently they are able to connect to the VPN and access outside resources, but they are unable to see any of the devices on the inside.    
I have created a user, pronto which should be forced in recieving the mdc3 connection profile which assigns them an IP address from my DHCP server which is also on that lan segment.  The VPN users are currently reciving an address from DHCP. In my case 10.10.10.20 was assigned to pronto when he VPN'd in.
My goal is to determine why pronto can't access any of the devices on the haklab interface
Here is the full config:
https://gist.github.com/3333437
ASDM VIEW ACCESS: just PM me and Ill create an account.
relevant snippets:
object network MDC3_VPN
subnet 10.10.10.200 255.255.255.248
access-list haklab_access_in extended permit ip object MDC3_VPN interface HAKlab
ip local pool mdc3_VPN 10.10.10.200-10.10.10.240 mask 255.255.255.0
nat (inside,outside) source static HAK_LAB HAK_LAB destination static MDC3_VPN MDC3_VPN
nat (outside,outside) after-auto source dynamic MDC3_VPN interface
username pronto password xxxxxxxx encrypted
username pronto attributes
vpn-group-policy mdc3_policy
group-lock value mdc3
service-type remote-access
webvpn
  anyconnect profiles value MDC3 type user
anyconnect profiles MDC3 disk0:/mdc3.xml
tunnel-group mdc3 type remote-access
tunnel-group mdc3 general-attributes
address-pool mdc3_VPN
default-group-policy mdc3_policy
dhcp-server subnet-selection 10.10.10.25
tunnel-group mdc3 webvpn-attributes
group-alias mdc3 enable
group-policy mdc3_policy internal
group-policy mdc3_policy attributes
wins-server none
dns-server value 10.10.10.25 4.2.2.2
vpn-tunnel-protocol ikev2 ssl-client
default-domain value mdc3.net
webvpn
  anyconnect profiles value MDC3 type user

Hi Daniel.
I am trying to figure out what are you trying to achive by this ACL?
"access-list haklab_access_in extended permit ip object MDC3_VPN interface HAKlab"
Why not use the below since you want to access all resources behind HAKlab.
access-list haklab_access_in extended permitip object MDC3_VPN any
HTH
Zubair

Similar Messages

  • One more with iChat problems - but one system works, the other doesn't!

    This might be an interesting addition to the discussions regarding not being able to connect via iChat.
    - I'm using 10.4.8 on my Intel iMac and my G4 PowerBook.
    - Both are running iChat 3.1.6 (v441)
    - Both are connected via their built-in Airport cards
    - Both OS X firewalls are on, but no iChat ports are being forwarded
    - no iChat ports are being forwarded in the router either
    - The firewall in the router is turned off
    Unfortunately my PowerBook does not have a camera, so I can only try text and audio. Text works on both systems.
    Audio on the PowerBook works like a charm using the appleu3test accounts. On the iMac I get this error immediately:
    Date/Time: 2007-01-16 22:33:58.086 -0800
    OS Version: 10.4.8 (Build 8L2127)
    Report Version: 4
    iChat Connection Log:
    AVChat started with ID 3715281537.
    blafusel5: State change from AVChatNoState to AVChatStateWaiting.
    0xc5e0d60: State change from AVChatNoState to AVChatStateInvited.
    0xc5e0d60: State change from AVChatStateInvited to AVChatStateConnecting.
    blafusel5: State change from AVChatStateWaiting to AVChatStateConnecting.
    0xc5e0d60: State change from AVChatStateConnecting to AVChatStateEnded.
    Chat ended with error -7
    blafusel5: State change from AVChatStateConnecting to AVChatStateEnded.
    Chat ended with error -7
    Video Conference Error Report:
    @:0 type=4 (00000000/0)
    [VCSIP_INVITEERROR]
    [19]
    @SIP/SIP.c:2437 type=4 (900A002D/0)
    [SIPConnectIPPort failed]
    Video Conference Support Report:
    @SIP/Transport.c:1218 type=1 (00000000/0)
    [INVITE sip:[email protected] SIP/2.0
    Via: SIP/2.0/UDP m.0;branch=z9hG4bK6c04c07c5a0cc1da
    Max-Forwards: 70
    To: "u0" <sip:[email protected]>
    From: "blafusel5" <sip:[email protected]>;tag=1482986134
    Call-ID: b4812924-a5f4-11db-928f-a054765613c4@lip
    CSeq: 1 INVITE
    Contact: <sip:[email protected]>;isfocus
    User-Agent: Viceroy 1.2
    Content-Type: application/sdp
    Content-Length: 463
    v=0
    o=cape 0 0 IN IP4 m.0
    s=blafusel5
    c=IN IP4 m.0
    b=AS:2147483647
    t=0 0
    a=hwi:1056:2:2160
    a=bandwidthDetection:YES
    a=iChatEncryption:NO
    m=audio 16384 RTP/AVP 12 3 0
    a=rtpmap:3 GSM/8000
    a=rtpmap:0 PCMU/8000
    a=rtpID:698458300
    m=video 16384 RTP/AVP 126 34
    a=rtpmap:126 X-H264
    a=fmtp:34 imagesize 0 rules 30:352:288
    a=framerate:20
    a=RTCP:AUDIO 16385 VIDEO 16385
    a=pogo
    a=fmtp:126 imagesize 0 rules 20:640:480:640:480
    a=rtpID:-1334120724
    @:0 type=2 (00000000/0)
    [VCAUDIO_OUTGOINGATTEMPT]
    [2]
    Video Conference User Report:
    and, for completion's sake, here the log when I try to Video chat using the iMac:
    Date/Time: 2007-01-16 22:35:40.006 -0800
    OS Version: 10.4.8 (Build 8L2127)
    Report Version: 4
    iChat Connection Log:
    AVChat started with ID 2290820685.
    blafusel7: State change from AVChatNoState to AVChatStateWaiting.
    0xc521e00: State change from AVChatNoState to AVChatStateInvited.
    0xc521e00: State change from AVChatStateInvited to AVChatStateConnecting.
    blafusel7: State change from AVChatStateWaiting to AVChatStateConnecting.
    0xc521e00: State change from AVChatStateConnecting to AVChatStateEnded.
    Chat ended with error -7
    blafusel7: State change from AVChatStateConnecting to AVChatStateEnded.
    Chat ended with error -7
    Video Conference Error Report:
    @:0 type=4 (00000000/48)
    [VCSIP_INVITEERROR]
    [19]
    @SIP/SIP.c:2437 type=4 (900A002D/48)
    [SIPConnectIPPort failed]
    Video Conference Support Report:
    @SIP/Transport.c:1218 type=1 (00000000/0)
    [INVITE sip:[email protected] SIP/2.0
    Via: SIP/2.0/UDP m.0;branch=z9hG4bK4276e4401b10a2d2
    Max-Forwards: 70
    To: "u0" <sip:[email protected]>
    From: "blafusel7" <sip:[email protected]>;tag=1930297757
    Call-ID: efacc012-a5f4-11db-928f-abb0c38013c4@lip
    CSeq: 1 INVITE
    Contact: <sip:[email protected]>;isfocus
    User-Agent: Viceroy 1.2
    Content-Type: application/sdp
    Content-Length: 463
    v=0
    o=cape 0 0 IN IP4 m.0
    s=blafusel7
    c=IN IP4 m.0
    b=AS:2147483647
    t=0 0
    a=hwi:1056:2:2160
    a=bandwidthDetection:YES
    a=iChatEncryption:NO
    m=audio 16386 RTP/AVP 12 3 0
    a=rtpmap:3 GSM/8000
    a=rtpmap:0 PCMU/8000
    a=rtpID:471213042
    m=video 16384 RTP/AVP 126 34
    a=rtpmap:126 X-H264
    a=fmtp:34 imagesize 0 rules 30:352:288
    a=framerate:20
    a=RTCP:AUDIO 16387 VIDEO 16385
    a=pogo
    a=fmtp:126 imagesize 0 rules 20:640:480:640:480
    a=rtpID:-1679698416
    @:0 type=2 (00000000/48)
    [VCVIDEO_OUTGOINGATTEMPT]
    [4]
    Video Conference User Report:
    I'm a bit stuck at the moment, as I can't reproduce what's different between the two systems. Btw, I did try this using the root account, just to make sure no 3rd party app is interfering.
    Any help greatly appreciated! I kinda like using iChat over Skype (which works on both systems btw.)

    I just tried connecting to you, and I got the same error message as with Apple's test accounts:
    Date/Time: 2007-01-17 19:02:33.806 -0800
    OS Version: 10.4.8 (Build 8L2127)
    Report Version: 4
    iChat Connection Log:
    AVChat started with ID 2481941854.
    [email protected]: State change from AVChatNoState to AVChatStateWaiting.
    0xcb97ba0: State change from AVChatNoState to AVChatStateInvited.
    0xcb97ba0: State change from AVChatStateInvited to AVChatStateConnecting.
    [email protected]: State change from AVChatStateWaiting to AVChatStateConnecting.
    0xcb97ba0: State change from AVChatStateConnecting to AVChatStateEnded.
    Chat ended with error -7
    [email protected]: State change from AVChatStateConnecting to AVChatStateEnded.
    Chat ended with error -7
    Video Conference Error Report:
    @:0 type=4 (00000000/48)
    [VCSIP_INVITEERROR]
    [19]
    @SIP/SIP.c:2437 type=4 (900A002D/48)
    [SIPConnectIPPort failed]
    Video Conference Support Report:
    @SIP/Transport.c:1218 type=1 (00000000/0)
    [INVITE sip:[email protected]:61360 SIP/2.0
    Via: SIP/2.0/UDP m.0;branch=z9hG4bK6e776f475ee10e9d
    Max-Forwards: 70
    To: "u0" <sip:[email protected]:61360>
    From: "[email protected]" <sip:[email protected]>;tag=157038870
    Call-ID: 56c09a8e-a6a0-11db-bfb6-ddda406413c4@lip
    CSeq: 1 INVITE
    Contact: <sip:[email protected]>;isfocus
    User-Agent: Viceroy 1.2
    Content-Type: application/sdp
    Content-Length: 472
    v=0
    o=cape 0 0 IN IP4 m.0
    s=[email protected]
    c=IN IP4 m.0
    b=AS:2147483647
    t=0 0
    a=hwi:1056:2:2160
    a=bandwidthDetection:YES
    a=iChatEncryption:YES
    m=audio 16386 RTP/AVP 12 3 0
    a=rtpmap:3 GSM/8000
    a=rtpmap:0 PCMU/8000
    a=rtpID:545783740
    m=video 16384 RTP/AVP 126 34
    a=rtpmap:126 X-H264
    a=fmtp:34 imagesize 0 rules 30:352:288
    a=framerate:20
    a=RTCP:AUDIO 16387 VIDEO 16385
    a=pogo
    a=fmtp:126 imagesize 0 rules 20:640:480:640:480
    a=rtpID:1139151121
    @:0 type=2 (00000000/48)
    [VCVIDEO_OUTGOINGATTEMPT]
    [4]

  • One email works, the other not so much

    I have 2 emails setup on my blackberry,
    My yahoo account which receives and sends fine,
    My 2nd account is a  work account, This account receives emails just fine and replies to everyone EXCEPT others people on my network.
    So i can't reply to anyone I work with ... any thoughts?

    when you send a mail, what is your From: address ? the one from your company ?
    The search box on top-right of this page is your true friend, and the public Knowledge Base too:

  • Why wont this jar execute (one way fine, the other is not)

    Without using a executable jar this works fine:
    java.exe -classpath myproject\classes;lib1.jar;lib2.jar;lib3.jar MyMainClass
    MyMainClass is my target class stored in myproject\classes
    I make an executable jar called Project.jar (basically all content in myproject\classes with usual manifest file containing target class) and then try
    java.exe -classpath lib1.jar;lib2.jar;lib3.jar -jar Project.jar
    This does not work and gives error:
    Exception in thread "main" java.lang.NoClassDefFoundError: org/springframework/beans/factory/InitializingBean
    The class org/springframework/beans/factory/InitializingBean is contained in lib1.jar
    I must be missing something fundamental about creating executable jars?? Any ideas or pointers?

    I've simplified my problem so someone could help me please!!!!
    The following runs fine:
    java -cp .;Model.jar TestThe following fails:
    java -cp .;Model.jar -jar Test.jarException in thread "main" java.lang.NoClassDefFoundError: Model at Test.main(Test.java:8)
    Model.jar contains one class model.Model.class
    Test.jar contains one class Test.class plus manifest file. The Test class simple does the following:
    import model.Model;
    public class Test
      public static void main(String[] args)
        System.out.println("Start");
        Model model = new Model();
        System.out.println("End");   
    }Any ideas why?

  • HT202213 I can view the library from one pc on the other but not the other way?

    I can view my wifes library on my pc in sharing but she cannot access mine. Any Ideas?

    Hello tj2k15,
    Thanks for using Apple Support Communities.
    To troubleshoot this issue with Messages on your iPhone please follow the troubleshooting in the support article linked to below.
    iOS: Troubleshooting Messages
    Take care,
    Alex H.

  • Duplicate identical songs. both play.After I delete one, the other will not play...itunes cannot locate it

    I have duplicate songs in itune library. Both songs will play, but if I delete a one of them the other will not play.  The message given in itunes is cannot locate the file, and neither can I. Any suggestions?

    I figured this out - this might be of great help to some people who have the same problem. I do not know how, but somehow my external hard drive got renamed to a different drive letter, from E to F. That's why itunes wasn't recognizing my songs, because there was a new file path name. Here's a microsoft XP tutorial on how to change drive letters if this happens to you:
    http://support.microsoft.com/kb/307844

  • How does one do a two way contacts sync between an iphone and outlook? Most of the community has answered as this to be "always so", but it does not work! Changes made on outlook get done in my iPhone, but it does not work the other way around!

    How does one do a two way contacts sync between an iphone and outlook? Most of the community has answered as this to be "always so", but it does not work! Changes made on outlook get done in my iPhone, but it does not work the other way around!

    Close the tab the web page is loaded in (command - W).

  • Why is one of my earphones working and the other is not?

    why is on of my earphones working and the other is not?

    Either it isn't plugged in all the way, the headphones are defective, or the headphone jack on your Touch is broken.

  • How do I set upmy Imac to allow using both my computer speakers and a Bose SoundLink system as outputs at the same time.  I can use one or the other, but not both.

    how do I set up my Imac to allow using both my computer speakers and a Bose SoundLink system as outputs at the same time.  I can use one or the other, but not both.  From systems Preferences I must select one or the other.  I want both to work all the time.

    Hi,
    I would recommend you to use 0FI_AP_4 rather using both, particularly for many reasons -
    1. DS: 0FI_AP_4  replaces DataSource 0FI_AP_3 and still uses the same extraction structure. For more details refer to the OSS note 410797.
    2. You can run the 0FI_AP_4 independent of any other FI datasources like 0FI_AR_4 and 0FI_GL_4 or even 0FI_GL_14. For more details refer to the OSS note: 551044.
    3. Map the 0FI_AP_4 to DSO: 0FIAP_O03 (or create a Z one as per your requirement).
    4. Load the same to a InfoCube (0FIAP_C03).
    Hope this helps.
    Thanks.
    Nazeer

  • In my firefor options window I have two zipped folders one allows me to brows and see what is inside the other does not give me this option. how can I see what is inside please?

    I have had MyWebSearch install itself as my primary browser....I have needed to reset Firefox in safe mode but I am not sure that the changes have actually been done! In Options in the Options menu the window displays all the add on's and features that are on Firefox....I have two zipped folders here One allows me to see inside the other does not. How do I access this one that does not give me the option to as I want to know what is inside...as this "MyWebSearch has been an enormous hassle...and needless to say has compromised my PC and the security of all of my passwords.....I want to be sure that the resetting the browser default has actually worked and that MyWebSearch is gone!
    Regards
    Coco

    Are you talking about MyWebSearch toolbar (http://help.mywebsearch.com/sbar2.html#q1) which offers apps such as Smiley Central, Cursor Mania???
    If yes, uninstallation instructions are here - (http://help.mywebsearch.com/sbar2.html#q4). Could you provide me some details about the ZIP folders. If I get a screenshot, I can help you very well.

  • The button on my Ipod Touch (the big one just below the screen) will not work when I press it. Nothing happens, when before it would wake my IPod out of sleep mode, and exit out of programs I was using. Now, no reactions. What should I do?

    The button on my Ipod Touch (the big one just below the screen) will not work when I press it. Nothing happens, when before it would wake my IPod out of sleep mode, and exit out of programs I was using (ex. ITunes or Safari to main screen) . Now, no reactions. When I press the button, it appears to be more indented then it was before. What should I do? Do I need to get it fixed or replaced, or is this a problem I can fix on my own? Whatever it is, I really need some advice. Thanks in advance.

    Try:
    fix for Home button
    iPhone Home Button Not Working or Unresponsive? Try This Fix
    - If you have iOS 5 and later you can turn on Assistive Touch it add the Home and other buttons to the iPods screen. Settings>General>Accessibility>Assistive Touch
    - If not under warranty Apple will exchange your iPod for a refurbished one for:
    Apple - Support - iPod - Repair pricing
    You can do it an an Apple store by:
    Apple Retail Store - Genius Bar
    or sent it in to Apple. See:
    Apple - Support - iPod - Service FAQ
    - There are third-party places like the following that will repair the Home button. Google for more.
    iPhone Repair, Service & Parts: iPod Touch, iPad, MacBook Pro Screens

  • How do I adjust the page orientation in Pages?  I want to keep the pages above the section break as portrait, and the ones below I want to change into landscape.  Is this possible?  I can only get it to be one or the other but not both.

    I want to keep the pages above the section break as portrait, and the ones below I want to change into landscape.  Is this possible?  I can only get it to be one or the other but not both.

    The work around is to do two documents, one in portrait format and one in landscape format. When finished export to Pdf. open in Preview by select both files and use Cmd + O or doubleclick. You can now in Previews thumbnail column the pages from one document into the other and then save.
    If you have created only one with i.e. all pages in portrait format but with the content for the landscape pages rotated on the pages, you can rotate the pages in Preview. Two ways to get the same result.

  • How do I create both endnotes and footnotes in same doc in Pages? I have iWork 2008. I understand how to create one or the other, but not both.

    How do I create both endnotes and footnotes in same doc in Pages? I have iWork 2008. I understand how to create one or the other, but not both.

    You have to select one or the other.
    Try making two documents and see if you can merge the .pdfs, but their will be problems with page flow, making the pages shift. Can't see it working really.
    Pages is not the only solution out there or the best for most jobs (let alone the safest). Try Word for Mac, LibreOffice (free) or any App that has the features you need.
    Peter

  • Does anyone knows a way to work with various Pages documents at the same time, for example with a system of tabs to switch directly from one document to the other?

    Hello everyone,
    Working with numerous Apple Pages documents at the same time, I am looking for an efficient solution to switch faster from one document to the other. Integrating all them in a single framework, for exemple by switching from one to the other with a system of tabs would be of great help. Does anyone knows if such a possibility exists?
    Thanks in advance,
    Jean-Baptiste

    jbp- wrote:
    Thanks. It works and is very efficient. Not as much as a real system of tabs, but is allows to switch very fast between different documents. Only regret I would have is that it doesn't work with a document which is on full page mode. But that's already very helpful!
    You're very welcome but Peggy really gave you the answer already. 
    With regard to the full screen apps, I don't think Apple have yet worked out how to make them elegantly coexist with other apps.  The closest you can get is the four finger swipe gestures you may use on a trackpad if you have one (Mission Control and App Exposé).
    In fact nowadays I use the App Exposé (four finger swipe down gesture) more often than I use Command-Accent to move between documents in the same app (when not in full screen).  It also as the advantage of showing you thumbnails of recently opened documents below the ones already open within the app.  If you haven't tried it, I suggest you give it a whirl.
    I can't remember now but I think the four finger gestures are not enabled by default and you must switch them on in System Preferences > Trackpad > More Gestures. 

  • One email account sends and receives emails, the other does not

    I have two different email accounts set up on my phone. They both worked, until I had my phone was serviced and wiped clean. Now one account sends and receives and the other does not. I have tried everything from deleting the account on the phone and rebooting, to changing my password. When I reactivate the account I get a message saying  "activation server" and that messages will be forwarded within 20 minutes and they never come. I'm not sure what else to try.

    Hello dalite and welcome to the BlackBerry® Support Community Forums.
    Sorry to hear you are having email issues.
    What type of email are you unable to receive - Gmail? Hotmail? Internet Service Provider hosted email?
    What is your BlackBerry PIN to investigate? 
    When you go to send an email using this account, do you get an error? Are you able to select this email account for sending an email?
    Thanks!
    -HMthePirate
    Come follow your BlackBerry Technical Team on twitter! @BlackBerryHelp
    Be sure to click Kudos! for those who have helped you.Click Solution? for posts that have solved your issue(s)!

Maybe you are looking for

  • How to Move Offline Files Cache in Windows 7?

    I'm using the offline files feature in Win7 (much better implementation, btw - kudos!) and I've run into a problem:  the CSC is using up all the drive space on C:\.  I'd like to move the CSC to D:\, however I've been unable to do so. I've seen this p

  • GPS maps on 8820 for Ukraine

    Hello! Where could I get the GPS maps for Ukraine? I see that maps for South America are very detalized since Kyiv is marked only as a dot. Please help me to obtain that maps. Thank you! WBR, Roman V. Sytnik

  • I/O error when exporting

    I just finished a 1.5 hr presentation. When I export to QT, the dialog indicates it will take seven minutes, then I get I/O error. David

  • How to transfer songs from a windows 7 pc to ipod

    i'm having problems ith transferring songs from windows 7 pc to ipod touch....anyone help

  • Tax code in A/R Invoice drops when the Ware House Code is changed

    Hello All, I am Using SAP Business One 2005A PL12 with Canadian Settings. When I add an Item in the A/R Invoice, it comes with a default TAXCODE, but when i change the ware house code the Taxcode drops, Can any one tell me why is this so? Thanks in a