Cisco VPN and Cisco 2651 customer support

I 2651 and remote VPN client

Client can successfully establish VPN to 2651 but nothing through this tunnel. In the stats customers there are no decrypted packets. In 2651 I saw the incoming packets but no response. What evil? (This cisco also make VPN tunnel with each other)

2651 config:

version 12.3

customer password username

AAA new-model

AAA authentication login userauthen local

AAA - the id of the joint session

crypto ISAKMP policy 3

BA 3des

preshared authentication

Group 2

!

crypto ISAKMP policy 10

md5 hash

preshared authentication

ISAKMP crypto key xxxx address xx.xx.xx.xx

ISAKMP crypto nat keepalive 20

!

ISAKMP crypto client configuration group 3000client

xxxxxxxxxxxx key

DNS 192.168.77.1

win 192.168.77.1

area xxx.xx

pool ippool

ACL 111

!

!

Crypto ipsec transform-set esp - esp-md5-hmac M-Chel

!

Crypto-map dynamic dynmap 10

game of transformation-M-Chel

!

!

card crypto client TunnelMap of authentication list userauthen

card crypto isakmp authorization list groupauthor TunnelMap

client configuration address card crypto TunnelMap answer

map TunnelMap 1 ipsec-isakmp crypto

defined peer xx.xx.xx.xx

game of transformation-M-Chel

match address 110

map TunnelMap 10-isakmp ipsec crypto dynamic dynmap

!

!

!

interface FastEthernet0/0

Description link to DMZ

IP address xxx.xxx.xxx.252 255.255.255.224

no ip route cache

no ip mroute-cache

automatic duplex

automatic speed

No cdp enable

no cache route NCLC

NAT outside IP

card crypto TunnelMap

!

interface FastEthernet0/1

Description network internal

IP 192.168.77.17 255.255.255.0

no ip route cache

no ip mroute-cache

automatic duplex

automatic speed

No cdp enable

NAT outside IP

no cache route NCLC

!

local pool IP 192.168.10.1 ippool 192.168.10.50

IP nat inside source list 1 interface FastEthernet0/0 overload

IP route 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xxx permanent

!

access-list 110 permit ip 192.168.77.0 0.0.0.255 host xx.xx.xx.xx

access-list 111 allow ip 192.168.77.0 0.0.0.255 192.168.10.0 0.0.0.255

Two things:

You have not defined a group of authorization specifying that authorization for VPN clients will be done locally. Add the following:

AAA authorization groupauthor LAN

And your NAT statement is probably wrong, even if you have not shown that the ACL 1 is equal to. follow these steps:

IP nat inside source list 100 int fa0/0 overload

access-list 100 deny ip 192.168.77.0 0.0.0.255 host xx.xx.xx.xx

access-list 100 deny ip 192.168.77.0 0.0.0.255 192.168.10.0 0.0.0.255

access-list 100 permit ip 192.168.77.0 0.0.0.255 any

no nat ip within the source list 1 int Fa0/0 overload

Note that if you get an error after this last order saying NAT entries are in use, leave the config mode, do:

clear the ip nat trans *.

return to mode config, and then retype the command. You must make sure that when you do a 'wr t', there is only a single command 'ip nat inside source... ". "in the config and it is the one that refers to ACL 100.

Tags: Cisco Security

Similar Questions

Maybe you are looking for

  • Playstaion 3 and computers__

    Remember - this is a public forum so never post private information such as numbers of mail or telephone! Ideas: how to hang a playstaion 3 to a computer You have problems with programs Error messages Recent changes to your computer What you have alr

  • How do I customize my computer with Microsoft PlayReady? [PlayReady error: 8004B81D]

    I received an e-book from Toshiba book pace, but as I tried to open it to read the book, a box with the word "BOLD" letter "Caution" appeared.  In the box, there was a statement that read "this computer must be individualized with Microsoft PlayReady

  • replacement of drive C

    have a G70t200 CTO - hasdisappeared 'computer' display CD player does not work.  Need a replacement for HL-DT-ST DVDram GSA T50N ATA. have no lightscribe or 2 ability to burn aside function.  Can anyone recommend a simple CD - dvd drive?

  • Backup is not completed successfully: error 0 x 80070032

    I set up a scheduled backup of Windows 7 last week and was able to perform manual backups a few. Today, the continuous backup fault just after the end of the system image backup. The error is 0 x 80070032. I can't find any information on this error c

  • Error of libraries ' Documents.libraries - ms no longer works.

    Original title: Windows 8 libraries I can't access any of my documents or photos that I get the message ' Documents.libraries - ms no longer works. How can I find my files?