Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > ASA 5505 as hardware vpn client to PIX 501 or ASA 5505 with network extension mode activated

Reply
Thread Tools

ASA 5505 as hardware vpn client to PIX 501 or ASA 5505 with network extension mode activated

 
 
bjorn@kumlait.se
Guest
Posts: n/a
 
      06-16-2007
Hi!

We have been using a PIX 501 for a couple of years now to access a
local network with Cisco VPN software client. However we now need
access from another site with multiple users so I decided to buy two
ASA 5505 UL bundle to do the job. First i tried to just hook up the
new ASA at the remote site and connect to the PIX 501 with easy vpn.
In went fine. I configured the new ASA right from the box with the old
vpn profile settings and it worked right away. But as we also need the
remote site to be accessed from the main site (PIX side) i tried to
enable "network extension mode" but then the tunnel didnt work
anymore. it connects but no traffic is coming through. I set it back
to normal mode (only client) and it worked again.

Is there anything else I need to do to be able to use network
extension mode than just enabling it in ASDM ?

The samt thing happens when using two ASA 5505 the same way.

Software versions are:

PIX: 6.3

ASA 5505: 7.2.1 (used to be 7.2.2 but I had to downgrade because of a
bug in 7.2.2 - vpnclient fails after reboot)

Thanks,

Bjorn

 
Reply With Quote
 
 
 
 
bjorn@kumlait.se
Guest
Posts: n/a
 
      06-17-2007
On 16 Juni, 14:21, b...@kumlait.se wrote:
> Hi!
>
> We have been using a PIX 501 for a couple of years now to access a
> local network with Cisco VPN software client. However we now need
> access from another site with multiple users so I decided to buy two
> ASA 5505 UL bundle to do the job. First i tried to just hook up the
> new ASA at the remote site and connect to the PIX 501 with easy vpn.
> In went fine. I configured the new ASA right from the box with the old
> vpn profile settings and it worked right away. But as we also need the
> remote site to be accessed from the main site (PIX side) i tried to
> enable "network extension mode" but then the tunnel didnt work
> anymore. it connects but no traffic is coming through. I set it back
> to normal mode (only client) and it worked again.
>
> Is there anything else I need to do to be able to use network
> extension mode than just enabling it in ASDM ?
>
> The samt thing happens when using two ASA 5505 the same way.
>
> Software versions are:
>
> PIX: 6.3
>
> ASA 5505: 7.2.1 (used to be 7.2.2 but I had to downgrade because of a
> bug in 7.2.2 - vpnclient fails after reboot)
>
> Thanks,
>
> Bjorn


Sorry for sending a reply to my own post but heres an update:

According to the log heres what happens when pinging the remote ip
192.168.1.201 using only "client mode":

6 Jun 17 2007 05:23:05 302020 192.168.1.201 192.168.10.2 Built ICMP
connection for faddr 192.168.1.201/0 gaddr 192.168.1.6/2 laddr
192.168.10.2/512

And heres what happens when pinging the remote ip 192.168.1.201 using
network extension mode:

302020 192.168.1.201 192.168.10.2 Built ICMP connection for faddr
192.168.1.201/0 gaddr 192.168.10.2/512 laddr 192.168.10.2/512faddr
192.168.1.201/0 gaddr 192.168.10.2/512 laddr 192.168.10.2/512

It seemes as the network extension mode does not set the correct
gateway (this case 192.168.1.6 which is the IP the vpn client get from
the PIX vpn pool).

Any ideas ?

Another bug ?

Thanks,

Bjorn

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: ASA 5505 behind ASA 5505 Dogg Child Cisco 0 06-07-2010 12:13 PM
ASA 5505 Remote Access VPN: client can not see internal network johnz Cisco 3 08-20-2009 02:14 PM
asa 5505 + l2l vpn + cisco client vpn lesniak81 Cisco 0 01-13-2009 09:59 AM
ipsec vpn between ASA 5505 and PIX 501 H. Steuer Cisco 2 03-23-2008 11:09 AM
PIX 501 VPN client to VPN client connections Nick Cisco 2 12-14-2005 04:33 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57