VPN Concentrator problem..

Discussion in 'Cisco' started by Dev, Mar 6, 2005.

  1. Dev

    Dev Guest

    Hi
    I have configure a Cisco VPN concentrator 3005 for PPTP VPN using local
    Authentication. My clients are behind a Microsoft ISA server. The VPN
    connection works fine with one client.

    Client ---->ISA Server ------>VPN Concentrator.


    But if other clients try to login, they fail. I have checked with
    concentrator log, it says "connection already established access
    denied." All clients are using Microsoft Dialup Connection for
    connecting VPN box.

    How can I make it work??
    Do I have to do somthing with NAT???

    ~/Dev
    Dev, Mar 6, 2005
    #1
    1. Advertising

  2. Dev

    Town Dummy Guest

    Most likely yes it is a nat problem. Because you didn't explain enough this
    is a guess.

    The MS ISA server is really nothing more than a piece of tin that keeps
    everything from working right. If you want your clients on the inside to go
    out through the ISA server then you will set their default route to go out
    that way and use that nat addressing scheme. If you want your incoming
    clients to come in through the concentrator then you will need to setup a
    different default gateway for them and also, you will to setup a different
    network and route to that network only on the inside.


    "Dev" <> wrote in message
    news:...
    > Hi
    > I have configure a Cisco VPN concentrator 3005 for PPTP VPN using local
    > Authentication. My clients are behind a Microsoft ISA server. The VPN
    > connection works fine with one client.
    >
    > Client ---->ISA Server ------>VPN Concentrator.
    >
    >
    > But if other clients try to login, they fail. I have checked with
    > concentrator log, it says "connection already established access
    > denied." All clients are using Microsoft Dialup Connection for
    > connecting VPN box.
    >
    > How can I make it work??
    > Do I have to do somthing with NAT???
    >
    > ~/Dev
    >
    Town Dummy, Mar 6, 2005
    #2
    1. Advertising

  3. Dev

    ESM Guest

    I'd move the concentrator outside of ISA. Put the Concentrators external
    interface on a switch with ISA's external interface and your edge router.

    "Dev" <> wrote in message
    news:...
    > Hi
    > I have configure a Cisco VPN concentrator 3005 for PPTP VPN using local
    > Authentication. My clients are behind a Microsoft ISA server. The VPN
    > connection works fine with one client.
    >
    > Client ---->ISA Server ------>VPN Concentrator.
    >
    >
    > But if other clients try to login, they fail. I have checked with
    > concentrator log, it says "connection already established access
    > denied." All clients are using Microsoft Dialup Connection for
    > connecting VPN box.
    >
    > How can I make it work??
    > Do I have to do somthing with NAT???
    >
    > ~/Dev
    >
    ESM, Mar 7, 2005
    #3
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. mikester
    Replies:
    4
    Views:
    16,732
    Eric Sorenson
    Feb 8, 2004
  2. Kai
    Replies:
    0
    Views:
    7,599
  3. Replies:
    4
    Views:
    2,004
    Scott Lowe
    Jun 26, 2005
  4. TechGuy
    Replies:
    3
    Views:
    5,839
    GizmoTech
    Feb 5, 2009
  5. Eitan
    Replies:
    0
    Views:
    487
    Eitan
    Mar 5, 2006
Loading...

Share This Page