VPN inside comments - can ping Web servers; cannot browse Internet sites

When connecting through my VPN Client, I ping "google.com", but cannot display Web sites in browsers (Proxy not necessary).

There is no error message in browsers, just an attempt without end to load websites that I go.

I use NAT and without VPN, everything works fine.

This problem does not occur if I use the network bridged - but is not option,

because it doesn't work for me at home and does not work with the University network - this laptop is also connected to.

Cisco VPN Client 5.0.04.0300 inside XP32-comments

The host also XP32

VMware Workstation 6.5.2

I don't know if this makes any difference, but it's a wireless connection (laptop)

That means THAT DNS is working. What is a proxy? Do you need to configure a proxy or one is configured, but you don't need one?

If you found this information useful, please consider awarding points to 'Correct' or 'Useful' responses Thank you!!

AWo

VCP / vEXPERT 2009

Tags: VMware

Similar Questions

  • Cannot access a Web site, but can ping IP addresses on the internet

    -With the help of Vista SP2 64-bit on laptop faulty.

    -Number of computers on the same network have access to the internet.

    -Tried several network interfaces on this laptop, but no luck for access to the network, wired or wireless

    -From this notebook, I can ping addresses Internet IP so the problem seems to be the side DNS.

    -Flushing DNS cache and reset the network interface.

    -Rebooted several times.

    What did I miss?

    Thanks in advance

    Hey easternguy,.

    Check if you can test the Web site by name.

    To do this:

    a. Click Start and type cmd.

    b. press ENTER.

    c. type the following command:

    ping hostname

    Ping uses name resolution to resolve a computer by IP address name. Therefore, if you successfully ping the IP address but you cannot ping a computer name, there is a problem with host name resolution, and no network connectivity.

    Case 1: If you can not ping the Web site using its address, follow these steps.

    In this case, try changing your host file.

    In the C:\Windows\System32\Drivers\etc Hosts files may be damaged or corrupted.

    Review the contents of your HOSTS file and compare it to the screenshot below. There is no need to worry about any line that starts with a # is ignored by Windows. In addition, the line "127.0.0.1 localhost" can be ignored without risk, because it is a standard input.

    Everything that appears in your HOSTS file without a # earlier this year, aside from the "127.0.0.1 localhost" line, should be regarded with suspicion when we try to diagnose the cause of the problem. The fastest way to test the involvement of HOSTS file is to just rename the host file. By changing the name of the HOSTS file, prevent us Internet Explorer to use it and so all problems caused by the file.

    Case 2:

    If you can ping external websites by IP address and name, but can't browse the web, probably your browser is misconfigured.

    Check that you do not have an incorrect Proxy Server affected necessary or not.

    For Internet Explorer, follow these steps.

    a. open Internet Explorer.

    b. go to Tools / Internet Options.

    c. click on the Connections tab.

    d. click the LAN Settings button.

    "e. uncheck both" "automatically detect settings" and "use a proxy server for your LAN '.

    This should be it.

    Kind regards

    Shinmila H - Microsoft Support

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • I can ping external IPs, but cannot browse Internet on Cisco 897VA sites

    I have a cisco 897va router I use a laboratory. I have a very basic config and am able to ping Web sites but for some reason any cannot browse one of them while connected to this router. The way it is currently Setup is port Gigabit 8 (WAN port) is connected to one of the switchports on my linksys router (connected to the cable modem), and I have a computer connected to the switchport Gigabit router 897VA Ccisco 0. Interface Vlan 1 is configured as my default gateway with the ip address of 192.168.1.1/24. I have a pool dhcp with the implemented network 192.168.1.0/24 which clients receive the ip configuration.  I'd appreciate any advice someone here can provide. Here is my config. I took off with a default interfaces (no) configurations in them for ease of reading:

    C897VA #show run

    Building configuration...

    Current configuration: 1985 bytes

    !

    ! 19:14:01 EST configuration was last modified Sunday, December 1, 2013

    ! NVRAM config update at 19:14:06 EST Sunday, December 1, 2013

    ! NVRAM config update at 19:14:06 EST Sunday, December 1, 2013

    version 15.2

    tcp KeepAlive-component snap-in service

    a tcp-KeepAlive-quick service

    horodateurs service debug datetime msec

    Log service timestamps datetime msec

    no password encryption service

    sequence numbers service

    !

    hostname C897VA

    !

    boot-start-marker

    boot-end-marker

    !

    !

    !

    No aaa new-model

    clock timezone IS - 5 0

    Crypto pki token removal timeout default 0

    !

    !

    no ip source route

    the 5 IP auth-proxy max-login-attempts

    max-login-attempts of the IP 5 admission

    !

    !

    !

    IP dhcp excluded-address 192.168.1.0 192.168.1.5

    !

    IP dhcp INTERNAL pool

    import all

    network 192.168.1.0 255.255.255.0

    default router 192.168.1.1

    domain cedanolab.com

    Server DNS 8.8.8.8 4.2.2.2 4.2.2.3

    !

    !

    8.8.8.8 IP name-server

    IP cef

    !

    !

    udi pid C897VA-M-K9 sn license *.

    !

    !

    !

    VDSL controller 0

    !

    !

    !

    ATM0 interface

    no ip address

    No atm ilmi-keepalive

    !

    interface Ethernet0

    no ip address

    !

    interface GigabitEthernet0

    no ip address

    !

    !

    interface GigabitEthernet8

    DHCP IP address

    NAT outside IP

    IP virtual-reassembly in

    automatic duplex

    automatic speed

    !

    interface Vlan1

    IP 192.168.1.1 255.255.255.0

    no ip redirection

    no ip proxy-arp

    IP nat inside

    IP virtual-reassembly in

    !

    IP forward-Protocol ND

    no ip address of the http server

    no ip http secure server

    !

    the IP nat inside source 1 list overload of the GigabitEthernet8 interface

    !

    access-list 1 permit 192.168.1.0 0.0.0.255

    !

    !

    Line con 0

    Synchronous recording

    line to 0

    line vty 0 4

    opening of session

    transport of entry all

    !

    Scheduler allocate 20000 1000

    !

    end

    C897VA #.

    Thank you in advance.

    Jeremias,

    If I understand you correctly, the PC connected to the Cisco router can resolve names to IP addresses and is able to ping outside the destination, but you can not browse the internet. Is this correct?

    I think an MTU problem. Even if your router connects Ethernet segments only, there may be an additional encapsulation somewhere along the way, by adding an extra burden to your packages and possibly causing them to become oversized. Can you try to add the ip tcp adjust-mss 1360 to your interface Vlan1 please and test connectivity again?

    Also, what exact IP address you receive via DHCP on your GigabitEthernet8 interface? Ideally, can you like after the output of the show ip route and show ip cef between your Cisco router? Also, please include the output of commands show ip cef 8.8.8.8 detail .

    Best regards

    Peter

  • Host Windows 7: Win XP Pro SP 3 comments: comments can ping hosts Internet but IE

    Problem: The customer is impossible to browse Internet hosts.  This virtual machine works great under Vista with the same version of VMWorkstation.

    Attempts to debug: take mail.yahoo.com.  I can ping.  But accessing http://mail.yahoo.com/ fails according to the and he tries so a search MSN and of course breaks down, too.

    C:\Documents and Settings\Administrateur & gt; ipconfig/all

    Windows IP configuration

    Name of the host...: squidney-cafdd0

    Primary Dns suffix...:

    Node... type: hybrid

    Active... IP routing: No.

    Active... proxy WINS: No.

    ... DNS suffix search list: localdomain

    Ethernet connection to the Local network card:

    The connection-specific DNS suffix. : localdomain

    ... Description: VMware accelerated AMD PCNet Adapter

    Physical address.... : 00-0C-29-E8-C0-C8

    DHCP active...: Yes

    Autoconfiguration enabled...: Yes

    ... The IP address: 192.168.203.129

    ... Subnet mask: 255.255.255.0.

    ... Default gateway. : 192.168.203.2.

    DHCP server...: 192.168.203.254

    DNS servers...: 192.168.203.2.

    Primary WINS server...: 192.168.203.2

    Lease obtained...: Sunday, June 21, 2009 20:02:54

    End of the lease...: Sunday, June 21, 2009 20:32:54

    C:\Documents and Settings\Administrateur & gt;

    Host: Windows 7 RC - Version 6.1.7100

    Client: Windows XP Pro SP 3 - Version 5.1.2600

    VMWorkstation version: 6.5 build - 156735

    Guest network: NAT

    Driver comments: VMware Accelerated AMD PCNet Adapter

    VMX file is attached

    vmsupport file is attached.

    Try to change your guest of NAT network to bridged.

  • Can ping printer but cannot print

    Hi all
    Not sure if this is the right forum, but it is a network printer, so I thought I would try it. My apologies if it should be elsewhere.

    I have here a user who is trying to print to a printer Samsung CLX-6200 from anywhere in Windows 7 (even a test page will not work). We can see the printer, we can interact with the properties, we can ping the printer. We can do just about everything except print.

    It is not a printer problem, like others on the network successfully print on the printer. It is not a print spooler problem, because the user can print to other printers on the network successfully. I assumed it was a corrupted driver or something, however to remove and then reinstall the device at no change results. I tried to connect directly to the printer (using a TCP/IP port) and connection via the print server. No luck.

    The print job appears in the print queue but does not print and eventually fails. The print processor is Winprint, I checked the logs, but found no errors.

    A complete reinstall, which I really don't want to do in deca (the user is in a remote office) I'm out of ideas.

    The user runs Win 7-32 bit on a Dell Vostro 3550.

    The following is based on my experience with XP; I haven't done a lot of work/research on Win 7 yet so I can't tell you absolutely that it will work, but it is worth trying.

    In general, printer drivers are installed using an INF file.  However, the first time that an installation is attempted, Windows 'compile' the relevant INF file in a companion PNF file with the same name.  For subsequent installations, Windows uses the PNF file.

    If you suspect a corrupted driver and download a new one, unless you have completely removed the old driver, including his PNF file, Windows will often use the old files.  You think that you install a new driver, but you're really not.

    In Windows XP, the solution had to go on 'Server properties' in the file menu of the windows printers and faxes and delete the suspicious driver from there.  In Windows 7, it's a little more complicated:

    Control Panel > system and security > administrative tools
    Print management
    In the left pane, expand print servers > > drivers
    Select the suspicious driver in the right pane and Delete (I don't know if you have to remove the complete package 'pilot' or not, that the option was not under XP).
    Now reinstall the driver.

    If the remote user does not use a "computer administrator" account, I suspect that you may need to "Print Management" right click and select 'run as administrator '.

    P.S.: Another procedure in XP was to use cleanspl.exe to Windows 2003 (available here--> http://www.microsoft.com/en-us/download/details.aspx?id=17657) Resource Kit.  According to this Technet thread, the same tool will work in Windows 7.

  • Cannot access internet sites - Satellite A30-92

    I have a laptop Satellite A30 - 92.

    Suddenly I'm unable to access most of the internet sites. Can I use it fine at high speed and on the LAN, but using the dial up, no.
    I can dial my ISP very well, but it will not download web page. Oddly enough I can get some (but very few sites), but above all no that I looked at the Device Manager and the modem works fine. Looking at the ports I have a ltp printer port, but no com port doesn't appear.

    This could be the cause and how to fix? Thank you.
    I must say I checked the firewall and even turned off.

    Must the connection by modem specific DNS and Proxy settings? Call them and find out.

    If you are using IE, try to disable Protected Mode.

    Or maybe just try another browser such as FireFox.

  • Cisco 5505, inside, I cannot ping the external IP of the router, but inside I can ping anything else

    Hello

    5505 Cisco's internal IP: 10.10.0.1 static, securty level 100

    External IP of Cisco 5505: 36.X.X.23 Dhcp, 0 security level

    of within peut all host external example ping by host 10.10.0.3 to google.com

    inside peut ping all domestic example of the host, host 10.10.0.3 to 10.10.0.5 included the internal IP of Cisco 10.10.0.1

    inside peut ping ip network address different on the same network from my router external example the host 36.x.x.25

    cannot ping inside the IP 36.X.X.23?

    from outside peuvent ping the IP 36.X.X.23

    outside peuvent ping different extenal network 36.X.X.X network ip

     
    How can I ping the 36.X.X.23 of the Interior, any suggestions?

    It's called background management which is not supported in the ASA

    https://Tools.Cisco.com/bugsearch/bug/CSCtd86651

    That's why is not and this will never work the ASA design does not

    It will be useful.

  • Comments can ping host, but host cannot ping the prompt.

    Hello. I already asked this question in another discussion, but it has a different title, so I decided to ask my question in a new discussion.

    Host: Windows 7, 192.168.186.1, no gateway IP

    Client: Windows XP, 192.168.186.2, no gateway IP

    If the ping of the comments reached the host. But when I try to ping the host's comments, I get '100% packet loss. How it could be explained?

    I take a look at the Windows Firewall on computers and make sure that it is disabled.

  • why I can not see servers on browser san andreas multiplayer?

    When I open samp (san andreas multiplayer), the servers just do not: O an idea why? And I now have windows vista (service pack 1).

    I reinstalled the game several times and still see no servers

    Here is the picture of my SEPM browser if it helps:

    http://www.upload.EE/image/626713/samp_no_servers.jpg

    And when I add a server, and then verify that: I do understand no/x /.

    http://www.upload.EE/image/626775/samp_info.jpg

    Please respond to someone why I can not see all the servers and how I can fix this problem? Thank you.

    Hello Artjom1993,

    Thank you for visiting the Microsoft answers community.

    You will need to contact the manufacturer to determine the cause of Word to locate servers through the application.

    Chris.H
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Cannot browse Internet in Vista Black Edition

    Respected Sir/Madam,

    IAM using vista black edition in what iam getting unknown problem Network. Local access only, so I ask you to please do need full for me iam trying two or three days to solve this problem

    If my problem was solve that you'll be very Appreciable in this case

    Thank you

    Respected Sir/Madam,

    IAM using vista black edition in what iam getting unknown problem Network. Local access only, so I ask you to please do need full for me iam trying two or three days to solve this problem

    If my problem was solve that you'll be very Appreciable in this case

    Thank you

    Hey Syed Mam

    Black Vista editions are manufactured or made NOT supported by microsoft and are a pirate pirate vista version

    I suggest that seek you assistance from where you downloaded

    Walter, the time zone traveller

  • I can ping guest-guest, but cannot telnet comments-comments

    Hello

    I have 3 VMs installed on my Windows 7 - Linux, Linux and Windows-7 host computer. Configuration of the network is NAT for all virtual machines. I added all the names of host hosts 3 hosts file all 4 machine. I can ping any one of these machines to any machine. But when I try to telnet to a linux computer virtual to another linux VM, I get the error message "no route to host".

    My goal is not not to run telnet but to check network connectivity. A linux machine has installed oracle database while the other linux machine has SQL customer demand. I can't do the SQL client to connect to the database on the other machine.

    Maybe I'm approaching it from the wrong angle. Any help would be appreciated.

    Maybee your nc behaves a little different from mine, the "... message was successful" will appear when I use - c. - z unreleased product, the only way to know if she did or didn't connect is by looking at the exit code. But is not serious.

    It finally hit me, another way to not get a "no route to host" - even if it is of course one - is if the host rejects the connection with a host/port ICMP unreachable. That must be it. The Cabinet of the oracle should be a firewall active and you must get to allow connections to port 1521.

    I really should have thought of that earlier: S guess I'm used to firewall using tcp-reset...

  • Cannot ping computers on the subnet remote site vpn while to set up

    Hi all

    I encountered a problem of site to site vpn for ping answered nothing of machines of remote subnet.

    the ipsec tunnel is ok but I can ping the ASA distance inside the interface ip

    Here is my scenario:

    LAN1 - ASA5510 - ASA5505 - LAN2 - ordinateur_distant

    LAN1: 192.168.x.0/24

    LAN2: 172.25.88.0/24

    remote_machine_ip: 172.25.87.30

    LAN1 can ping to ASA5505 inside interface (172.25.88.1)

    but cannot ping ordinateur_distant (172.25.87.30)

    Inside of the interface ASA5505 can ping ordinateur_distant

    LAN2 can ASA5510 ping inside the machines on LAN1 and interface

    Is there something I missed?

    Thanks much for the reply

    I don't think it's something you really want to do.

    If you PAT the whole subnet to LAN1 ip (192.168.1.0/24) to 172.25.249.1, then LAN2, will not be able to reach the specific host on LAN1, cause now, you represent the LAN1 network, with a single ip address.

    So traffic will become a way from LAN1 can reach LAN2 and get the response of LAN2 through the PAT on 172.25.249.1

    But LAN2, is no longer specific hosts LAN1 ip traffic, since you only have 172.25.249.1, to represent the subnet to LAN1.

    If you still want to PAT the whole subnet to LAN1 (192.168.1.0/24) ip to 172.25.249.1, then you have to do outside the NAT.

    http://www.Cisco.com/en/us/customer/docs/security/ASA/asa80/command/reference/no.html#wp1737858

    Kind regards

  • can ping but cannot browse after you update to SP3 of XP

    Hello

    I use a computer connected wireless to a DSL modem. There are also three other computers connect to the same ADSL router wirelessly and they work fine.

    The problem machine running Windows XP SP2 with automatic updates enabled. The computer connects to the Internet and works well, until he installed XP SP3. After restarting the installation of SP3, no normal Internet connection cannot be established with any browser. I tried Internet Explorer, Firefox and Google Crome. I just get an error page (Internet Explorer cannot display the web page) when you try to connect to any web page with a name. I can connect to a Web site through the IP address only. I can ping by IP address, but not by name.

    I reinstalled XP SP2 now, for the seventh time, left to run automatic updates and each time after SP3 installation starts the connection problem. I have not installed Norton or any other anti virus on the machine programs, still having the same problem. I disabled the same Windows Firewall! No protection, nothing that the operating system on the computer and cannot always surf the Internet when XP SP3 is installed. When I stop the automatic updates before you install SP3, I can browse normally without any problems.

    I searched through a large number of Web sites for a solution and trying all possible and impossible solutions offered: parameters examined, fixed network winsock, nothing seems to solve the problem.

    Any help will be appreciated.

    John

    AirOnSkin,

    You were right about the problem of dns, seems that I stared at the present time, even if it's just something temporary and not the real solution. Here's what I did:

    First, I examined parameters network (again!) and the ipconfig enough & / renew options, as suggested by Joselbarra. All were OK and I did not any changes.

    Then, I started playing with the ipconfig and ping commands in the command prompt window. I had my laptop next to the problem pc to compare the results of the pings I've tried. Ping and ping-a on the problem pc gave me exactly the same results, while ping - one on the phone gave me the name of the server!

    Last sentence of AirOnSkin did the trick. I tried ipconfig/all on the problem pc again and there was no ip address for the dns, while on my laptop, I got the ip address for the listed dns!

    So here is the temporary fix: in the TCP/IP settings I have the ip address specified for the dns and everything worked! For some strange reason the network settings is not get the IP for the dns automatically, and this happens only when I load XP SP3.

    Now, it is up to the technical expert to understand why not bring a real solution.

    Thanks for your help, guys!

    See you soon,.

    John

  • Vista can ping machine to another, but cannot access shared folders on the machine

    Hi experts,

    Recently, we have problems with some Vista machines to access shared folders on other Vista machines. This seems to happen after the automatic updates of windows.

    These 'problem' machines are able to ping other machines 'good' but is unable to connect to shared folders machines 'good '.

    The reverse works fine ('good' machines can ping and access 'problem' machines).

    When you connect to folders shared of these 'problem' to 'good' machines machines using \\machinename\folder or even \\machine_ip\folder, the error window "the network location cannot be reached" appears.

    'Problem' machines can do desktop connection remote for the machines 'good '.

    All machines have the parameters: -.

    Same workgroup

    Same domain - private network

    Network discovery on

    File sharing on

    Public folder sharing

    Password protected sharing

    I am not able to find a solution on the web site and microsoft.

    Re-install Vista on 1 machine of 'problem' and the problem goes away.

    The problem with reinstalling is subject to re-registration of certain software licenses which has no registration online (through applications for certificates).
    Is there a resolution without having to re - install Vista?

    ltkhoo

    Hey

    You can post your question here:

    http://social.technet.Microsoft.com/forums/en/category/windowsvistaitpro

  • Cisco 881 can ping internet but computers behind the router cannot

    I have a cisco 881, which can ping internet but not of any computer behind it. Computers receive a static IP address, that is why there is no DHCP assigned to any LAN interface. Here's the running configuration:

    Building configuration...

    Current configuration: 6435 bytes
    !
    ! Last modification of the configuration at 22:15:30 UTC Friday, March 11, 2016
    !
    version 15.5
    no service button
    horodateurs service debug datetime msec
    Log service timestamps datetime msec
    no password encryption service
    !
    router host name
    !
    boot-start-marker
    boot-end-marker
    !
    !
    logging buffered 51200 warnings
    !
    No aaa new-model
    BSD-client server url https://cloudsso.cisco.com/as/token.oauth2
    iomem 10 memory size
    !
    Crypto pki trustpoint TP-self-signed-76299383
    enrollment selfsigned
    name of the object cn = IOS - Self - signed - certificate - 76299383
    revocation checking no
    rsakeypair TP-self-signed-76299383
    !
    !
    TP-self-signed-76299383 crypto pki certificate chain
    certificate self-signed 01
    30820227 30820190 A0030201 02020101 300 D 0609 2A 864886 F70D0101 05050030
    2F312D30 2B 060355 04031324 494F532D 66 2 536967 6E65642D 43657274 53656C
    69666963 37363239 39333833 31333031 33313231 30333034 301E170D 6174652D
    5A170D32 30303130 31303030 3030305A 302F312D 302B 0603 55040313 24494F53
    2D53656C D 662 5369 676E6564 2D 436572 74696669 63617465 2 373632 39393338
    3330819F 300 D 0609 2A 864886 F70D0101 01050003 818 0030 81890281 8100B39C
    1F1F1B5A 620D3DB7 E4B82486 D8A6E928 E880F817 20D8D5D8 744 HAS 6985 B48A0AEF
    072919 6ABF6428 C 9 272B2F4E 28382554 1D1CC5CD 701F9646 38EEE5CE 67F475C4
    DD5B464B ECBD78AF A5B6B36B D2791CFE E6CB886F B030E179 7A209BC4 1CDC6BA1
    711616 C 4FD6BE16 4 489DCC5F A5EE9729 365858FD 1654EA5F 3B7F90B2 19470203
    010001A 3 53305130 1 130101 FF040530 030101FF 301F0603 551 D 2304 0F060355
    18301680 1465D9D2 8C6F18DF 98EF832A 03DE7ADD 97301 06 03551D0E D45A6C59
    04160414 65D9D28C 6F18DF98 EF832A03 DE7ADDD4 5A6C5997 300 D 0609 2A 864886
    818100A 6 05050003 928BFD76 AEE144B3 540415EE 7DC2339D B6142CF6 F70D0101
    60E3A6DF 06DA321C B711183C 80755902 2D1D9407 857F05ED B987C08D 25002B5F
    F3C0F996 8CDA1830 3F85456B 6C6F2A4B 774B93DC 256AB90E 5A46126C C2D044DB
    3B76F1A2 0E98D2F0 A0D656CF 5031C7D7 1D9D2F88 188927 4 EEAA3915 E97C7B83
    ECF7239B 5B7F0FDD E4C9CA
    quit smoking
    !
    !
    !
    !
    !
    !
    !
    !

    !
    DHCP excluded-address IP 192.168.136.22 192.168.136.30
    DHCP excluded-address IP 192.168.131.22 192.168.131.254
    !
    IP dhcp Internet pool
    network 192.168.131.0 255.255.255.0
    DNS-server 70.28.245.227 184.151.118.254
    router by default - 192.168.131.157
    !
    !
    !
    name of the IP-server 70.28.245.227
    name of the IP-server 184.151.118.254
    IP cef
    No ipv6 cef
    !
    !
    !
    !
    !
    Authenticated MultiLink bundle-name Panel
    !
    !
    !
    !
    !
    !
    !
    !
    CTS verbose logging
    udi pid C881-K9 sn FGL1927224B standard license
    !
    !
    Archives
    The config log
    hidekeys
    username * 15 secret 5 privilege TOHi $1$ $ xwZvR0n8p6r00xE5nnBE11
    !
    !
    !
    !
    !
    !
    !
    crypto ISAKMP policy 1
    BA 3des
    preshared authentication
    Group 2
    isakmp encryption key * address 96.45.14.xx
    !
    !
    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac
    tunnel mode
    Crypto ipsec transform-set ESP-3DES-SHA1 esp-3des esp-sha-hmac
    tunnel mode
    Crypto ipsec transform-set esp-SHA2-ESP-3DES-3des esp-sha-hmac
    tunnel mode
    Crypto ipsec transform-set esp-3des SHA3-ESP-3DES esp-sha-hmac
    tunnel mode
    !
    !
    !
    map SDM_CMAP_1 1 ipsec-isakmp crypto
    Description Tunnel to96.45.14.xx
    the value of 96.45.14.xx peer
    game of transformation-ESP-3DES-SHA2
    match address 102
    !
    !
    !
    !
    !
    !
    interface FastEthernet0
    no ip address
    !
    interface FastEthernet1
    no ip address
    !
    interface FastEthernet2
    no ip address
    !
    interface FastEthernet3
    switchport access vlan 2
    no ip address
    !
    interface FastEthernet4
    port WAN Description
    DHCP IP address
    response to IP mask
    NAT outside IP
    IP virtual-reassembly in
    automatic duplex
    automatic speed
    map SDM_CMAP_1 crypto
    !
    interface Vlan1
    Description of control network
    IP 192.168.131.157 255.255.255.0
    IP access-group VLAN1_In in
    IP nat inside
    IP virtual-reassembly in
    !
    local pool IP VPN 192.168.131.152 192.168.131.155
    default IP gateway - 174.0.0.1
    IP forward-Protocol ND
    IP http server
    23 class IP http access
    local IP http authentication
    IP http secure server
    IP http timeout policy slowed down 60 life 86400 request 10000
    !
    IP high speed-flyers
    Top 10
    Sorting bytes
    !
    IP route 0.0.0.0 0.0.0.0 174.0.0.1 permanent
    !
    VLAN1_In extended IP access list
    Note the incoming traffic
    Note the category CCP_ACL = 1
    Note the crosstalk
    deny ip 192.168.135.0 0.0.0.255 192.168.130.0 0.0.1.255
    deny ip 192.168.136.0 0.0.0.255 192.168.130.0 0.0.1.255
    Note the crosstalk
    deny ip 192.168.130.0 0.0.1.255 192.168.135.0 0.0.0.255
    deny ip 192.168.130.0 0.0.1.255 192.168.136.0 0.0.0.255
    allow an ip
    VLAN1_Out extended IP access list
    Note for diagnosis
    Note the category CCP_ACL = 1
    Note Diag
    IP enable any any newspaper
    allow_all extended IP access list
    Note the category CCP_ACL = 1
    IP enable any any newspaper
    !
    !
    Note category of access list 1 = 2 CCP_ACL
    access-list 1 permit 192.168.1.0 0.0.0.255
    Note access-list category 2 CCP_ACL = 2
    access-list 2 permit 192.168.130.0 0.0.0.255
    Note access-list 100 category CCP_ACL = 4
    Note access-list 100 IPSec rule
    access-list 100 permit ip 192.168.131.0 0.0.0.255 192.168.125.0 0.0.0.255
    Note access-list 100 IPSec rule
    access-list 100 permit ip 192.168.131.0 0.0.0.255 192.168.120.0 0.0.0.255
    Note access-list 101 category CCP_ACL = 4
    Note access-list 101 IPSec rule
    access-list 101 permit ip 192.168.131.0 0.0.0.255 192.168.125.0 0.0.0.255
    Note access-list 102 CCP_ACL category = 4
    Note access-list 102 IPSec rule
    access-list 102 permit ip 192.168.131.128 0.0.0.31 192.168.125.0 0.0.0.255
    Note access-list 103 CCP_ACL category = 4
    Note access-list 103 IPSec rule
    access-list 103 allow ip 192.168.131.0 0.0.0.255 192.168.125.0 0.0.0.255
    !
    control plan
    !
    !
    !
    MGCP behavior considered range tgcp only
    MGCP comedia-role behavior no
    disable the behavior MGCP comedia-check-media-src
    disable the behavior of MGCP comedia-sdp-force
    !
    profile MGCP default
    !
    !
    !
    !
    !
    !
    !
    Line con 0
    no activation of the modem
    line to 0
    line vty 0 4
    access-class allow_all in
    access-class allow_all out
    privilege level 15
    password *.
    opening of session
    transport telnet entry
    telnet output transport
    !
    max-task-time 5000 Planner
    Scheduler allocate 20000 1000
    !
    !
    WebVPN WAN gateway
    IP address 192.168.126.9 port 44443
    redirect http port 80
    SSL trustpoint TP-self-signed-76299383
    development
    !
    WebVPN context PLC
    WAN gateway
    !
    SSL authentication check all
    development
    !
    default group policy
    functions compatible svc
    SVC-pool of addresses "VPN" netmask 255.255.255.224
    SVC Dungeon-client-installed
    generate a new key SVC new-tunnel method
    SVC split include 192.168.131.0 255.255.255.224
    mask-URL
    by default-default group policy
    !
    end

    Any ideas?

    Thank you.

    I see ip nat inside and ip nat outside interfaces configured on. But I don't see any translation of address configured. This would preclude anything inside the unit to be able to access the Internet.

    HTH

    Rick

Maybe you are looking for