Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Networking > Cisco Security – PIX/ASA/VPN
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

1 Internet IP Static NAT and cisco vpn client?

1 Internet IP Static NAT and cisco vpn client?

this thread has 3 replies and has been viewed 1015 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 21st June 2012, 21:36
loudog3114 loudog3114 is offline
Casual
Casual
 
 Join Date: Jun 2012
  6 month star
 Posts: 3
 Reputation: loudog3114 is on a distinguished road (10)
Default 1 Internet IP Static NAT and cisco vpn client?

Is there any way to make the cisco vpn client work on the same external IP that is static natted?

I have to use the static nat because I need DNS rewrites, but that has killed external access using the cisco vpn client, as I beleive that traffic is being routed to the internal server. here is my config;

Result of the command: "show running-config"

: Saved
:
ASA Version 7.2(4)
!
hostname ciscoasa
domain-name default.domain.invalid
enable password ** encrypted
passwd ** encrypted
names
name 192.168.168.232 KLEIN
name 192.168.168.230 OPENFILER
!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.168.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address dhcp setroute
!
interface Vlan3
no forward interface Vlan1
nameif dmz
security-level 50
ip address 192.168.2.1 255.255.255.0
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
switchport access vlan 3
!
ftp mode passive
dns server-group DefaultDNS
domain-name default.domain.invalid
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
access-list outside_access_in extended permit tcp any interface outside eq 3389
access-list outside_access_in extended permit tcp any interface outside eq 32400
access-list inside_nat0_outbound extended permit ip any 192.168.168.64 255.255.255.224
access-list internallan standard permit 192.168.168.0 255.255.255.0
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
mtu dmz 1500
ip local pool vpnpool 192.168.168.70-192.168.168.80 mask 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-524.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 0.0.0.0 0.0.0.0
nat (dmz) 1 0.0.0.0 0.0.0.0
static (inside,outside) interface KLEIN netmask 255.255.255.255 dns
access-group outside_access_in in interface outside
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
http server enable
http 192.168.1.0 255.255.255.0 inside
http 192.168.2.0 255.255.255.0 dmz
http 192.168.168.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto dynamic-map outside_dyn_map 20 set pfs group1
crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.168.100-192.168.168.200 inside
dhcpd enable inside
!
dhcpd address 192.168.2.100-192.168.2.200 dmz
dhcpd enable dmz
!

group-policy DfltGrpPolicy attributes
banner none
wins-server none
dns-server none
dhcp-network-scope none
vpn-access-hours none
vpn-simultaneous-logins 3
vpn-idle-timeout 30
vpn-session-timeout none
vpn-filter none
vpn-tunnel-protocol IPSec l2tp-ipsec webvpn
password-storage enable
ip-comp disable
re-xauth disable
group-lock none
pfs disable
ipsec-udp disable
ipsec-udp-port 10000
split-tunnel-policy tunnelspecified
split-tunnel-network-list value internallan
default-domain none
split-dns none
intercept-dhcp 255.255.255.255 disable
secure-unit-authentication disable
user-authentication disable
user-authentication-idle-timeout 30
ip-phone-bypass disable
leap-bypass disable
nem disable
backup-servers keep-client-config
msie-proxy server none
msie-proxy method no-modify
msie-proxy except-list none
msie-proxy local-bypass disable
nac disable
nac-sq-period 300
nac-reval-period 36000
nac-default-acl none
address-pools none
smartcard-removal-disconnect enable
client-firewall none
client-access-rule none
webvpn
functions url-entry
html-content-filter none
homepage none
keep-alive-ignore 4
http-comp gzip
filter none
url-list none
customization value DfltCustomization
port-forward none
port-forward-name value Application Access
sso-server none
deny-message value Login was successful, but because certain criteria have not been met or due to some specific group policy, you do not have permission to use any of the VPN features. Contact your IT administrator for more information
svc none
svc keep-installer installed
svc keepalive none
svc rekey time none
svc rekey method none
svc dpd-interval client none
svc dpd-interval gateway none
svc compression deflate
group-policy kleinvpn internal
group-policy kleinvpn attributes
dns-server value 192.168.168.1 8.8.8.8
vpn-tunnel-protocol IPSec
username ** password ** encrypted privilege 0
username ** attributes
vpn-group-policy kleinvpn
tunnel-group kleinvpn type ipsec-ra
tunnel-group kleinvpn general-attributes
address-pool vpnpool
default-group-policy kleinvpn
tunnel-group kleinvpn ipsec-attributes
pre-shared-key *
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:b5c8a9d824e1e4b7d39fae239ebe16bf
: end
  #2  
Old 21st June 2012, 21:56
auglan's Avatar
auglan auglan is offline
Moderator
 
 Join Date: Apr 2010
  6 month star 12 month star
 Location: Raleigh, NC
 Posts: 1,179
 Reputation: auglan has a spectacular aura aboutauglan has a spectacular aura aboutauglan has a spectacular aura about (215)
Default Re: 1 Internet IP Static NAT and cisco vpn client?

I would do some debugging here to see what is going on when the vpn client tries to connect.


debug crypto isakmp


Have you tried removing the static nat as a test and see if they can connect then? The best option is to get a few public ip's from your provider and set this up right.
__________________
CCNA, CCNA-Security, CCNP
CCIE Security (In Progress)

Last edited by auglan; 21st June 2012 at 22:38..
  #3  
Old 25th June 2012, 14:23
jceb3167 jceb3167 is offline
Casual
Casual
 
 Join Date: Jun 2012
  6 month star
 Posts: 7
 Reputation: jceb3167 is on a distinguished road (10)
Default Re: 1 Internet IP Static NAT and cisco vpn client?

If you use NAT-T you shouldn't have any problem with that...
  #4  
Old 25th June 2012, 16:14
auglan's Avatar
auglan auglan is offline
Moderator
 
 Join Date: Apr 2010
  6 month star 12 month star
 Location: Raleigh, NC
 Posts: 1,179
 Reputation: auglan has a spectacular aura aboutauglan has a spectacular aura aboutauglan has a spectacular aura about (215)
Default Re: 1 Internet IP Static NAT and cisco vpn client?

NAT-T is for devices behind a nat device. This traffic is terminating on the ASA itself. (The ASA is the vpn server) Anyway NAT-T should be automatically negotiated between the server and client.I think the issue is an order of operations with NAT. Have you tried debugging phase 1 to see what the logs say?
__________________
CCNA, CCNA-Security, CCNP
CCIE Security (In Progress)

Last edited by auglan; 25th June 2012 at 16:23..
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with a XP client switching from Static IP to DHCP rlp4000 DHCP 7 27th April 2010 20:12
Static Ip - Now my internet connection is slow and times out constantly Bruceleeroy DSL, Cable, and other Broadband Issues 3 27th March 2009 11:21
Exchange on Static IP, Internet on Dynamic. pjclarke2008 Exchange 2000 / 2003 1 2nd September 2008 15:30
BIND 8.2.2 DNS Migration to Win 2k3 + DHCP Enable for static client Albertwt Windows Server 2000 / 2003 2 24th February 2008 10:11
Sharing: Determine TS dynamic client printer name for static application mapping. ahinson General Scripting 0 24th April 2007 21:00


All times are GMT +3. The time now is 21:34.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri