[VPN] cisco vpn3000, firewall policy, & linux client

Don Mills dmills at email2.dss.state.va.us
Wed Jun 25 12:51:20 EDT 2003


Yeah the VPN3000 series can push policy down to an integrated fw in their
windows client.
http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration
_example09186a0080094b02.shtml
It can be configured to not complete the connection without this working.
They should only need to do this if they have enabled split
tunnelling...anyway tell them to make you another group set up the same way
but without that option checked...


----- Original Message -----
From: "Kevin Geiss" <kevin at desertsol.com>
To: <vpn at lists.shmoo.com>
Sent: Tuesday, June 24, 2003 3:23 PM
Subject: [VPN] cisco vpn3000, firewall policy, & linux client


> I need to get connect to a cisco vpn3000 concentrator vpn in linux.
>
> I got everything working fine with cisco's vpn client on my win98 machine.
>
> but when I use the same config file I used in windows with the cisco
> vpn client for linux, the concentrator disconnects from me during the
> 'securing connection' phase.
>
> The admins in charge of the vpn3000 report this is caused by the
> concentrator 'pushing a firewall policy to the client. this feature is
> currently only supported in a windows environment.'
>
> does anyone know what they're talking about? and more importantly, is
> there some way I can get around this issue with my poor linux box? I'm
> willing to try FreeS/WAN or some other client if necessary.
>
> The irony is that I need to be able to access 2 linux boxes on the
> vpn! so it's quite annoying it only works in windows. :)
>
> thanks in advance.
> _______________________________________________
> VPN mailing list
> VPN at lists.shmoo.com
> http://lists.shmoo.com/mailman/listinfo/vpn



More information about the VPN mailing list