VPN Errors on multilink T1 - but inly for DHCP and not static NAT  users?

VPN Errors on multilink T1 - but inly for DHCP and not static NAT users?

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
VPN Errors on multilink T1 - but inly for DHCP and not static NAT users? lwpowers 04-04-2008
Posted by on April 4, 2008, 12:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a Cisco 1700 router with dual WIC/T1's

LAN users are assigned NAT IP addresses from the Cisco 1700 via DHCP
from 10.0.0.100 to 10.0.0.200.

10.0.0.2 - 10.0.0.15 are 1:1 configured to our 16 internet routable IP
addresses.

Users who receive an IP address via DHCP have all desired
functionality, including surfing, email, etc... however they cannot
establish a VPN.

The same users can statically assign a 1:1 IP address (i.e. 10.0.0.15)
and establish a VPN without any issue.

Im stuck. Anyone know why this is happening?


Posted by Tilman Schmidt on April 8, 2008, 4:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options
lwpowers@gmail.com schrieb:
> I have a Cisco 1700 router with dual WIC/T1's
>
> LAN users are assigned NAT IP addresses from the Cisco 1700 via DHCP
> from 10.0.0.100 to 10.0.0.200.
>
> 10.0.0.2 - 10.0.0.15 are 1:1 configured to our 16 internet routable IP
> addresses.
>
> Users who receive an IP address via DHCP have all desired
> functionality, including surfing, email, etc... however they cannot
> establish a VPN.
>
> The same users can statically assign a 1:1 IP address (i.e. 10.0.0.15)
> and establish a VPN without any issue.
>
> Im stuck. Anyone know why this is happening?

It's not too clear what you or your users are trying to do, but as a
wild guess, you may have hit the fact that standard IPSec does not work
across NAT. If so, you'll want to use the "NAT traversal" option.

HTH
T.

--
Please excuse my bad English/German/French/Greek/Cantonese/Klingon/...

Similar ThreadsPosted
PIX 515 - to static map users or let XLATE deal with them? January 23, 2007, 9:21 am
Moving users from NAT to static routable IP's October 12, 2006, 10:56 am
pix to pix dhcp to static vpn July 22, 2005, 9:10 am
Secondary addresses and static DHCP April 28, 2006, 6:11 pm
Csico DHCP static mapping September 26, 2007, 3:39 am
PIX 501 DNS Alias on interface for static IPs while port fowarding and DHCP? April 27, 2006, 10:11 pm
Configure Aironet 1100 with static ip and as a DHCP server June 7, 2006, 3:05 pm
Manual DHCP binding static-dynamic on 3750 August 15, 2006, 2:59 pm
50 users April 28, 2005, 12:34 pm
Monitoring VPN users on PIX 515 September 23, 2005, 11:16 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map