
Cisco ASA that won't allow L2TP/IPSEC from a Windows Client to off site?
What is the best way to trouble shoot this problem? I have a Windows XP client. The Cisco ATA is set to allow everything out bound and I've ever tried setting up an access rule to allow anything two/from this machine. Is there some way to make windows log what's wrong? The Error is the other end is not answering. I've tried this same laptop offsite and it's able to connect fine.
show version output:
Cisco Adaptive Security Appliance Software Version 7.2(3)
Device Manager Version 5.2(2)61
The link to the cisco site seems to be if you wanted to auth to another ASA device. i'm basicly just trying to pass through from a win XP box to a Win2k3 server out on the internet. Interestingly enough, I have no other kinds of VPN issues.
Hey there guy.
I had the same problem. First, do you have SmartNet? If so, call them! This is really what you pay for!
It is in your firewall. You have to specifically allow any to any udp port 4500 and any to any udp isakmp. If you do not see isakmp, you have to change it make it. It is port 500.
Cheers.
Tom
hummm....I did a bit more digging. What version of IOS do you have? That may make the difference in this being hard or easy.
The instructions I gave you were for Cisco client, not MS client. Try this out.....
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807213a7.shtml
I think though, you may want to evaluate how you are connecting to this remote site. I have checked around, and while possible, it is not that easy.
Tom
|