PDA

View Full Version : Cisco VPN Client won't work with TMobile Datacard


krakan
28-01-2007, 07:09 PM
Hi folks,

I came about the site when I was trying to get my datacard to work *at all* - was directed to the Option software which is now working fine for me.

Problem is, the main thing I need the card for is to be able to connect to customers Servers/PCs when I'm on the road. I'm able to do this fine where we have small sites with no especially clever security, but one or two have Cisco Firewalls and are configured only to allow VPN connections using the Cisco VPN Client.

Unfortunately, the VPN client /Tmobile Datacard combo just doesn't work!

I can use the VPN no probs via a LAN, WiFi or even Analogue Dialup connection, all on my laptop, but when I try and use the datacard, the Cisco VPN client seems to connect, but won't let me do anything else - can't ping the firewall, PCs or servers, can only ping myself..

Anyone else experienced this? I've tried it on 3 laptops and all the same. For the record, I think it also happens with the Vodafone cards, but I can't confirm this.

Any suggestions greatly appreciated!

bsrjl1
29-01-2007, 10:49 AM
Yes I've got the same thing with one of my VPN profiles, but the other works fine... Both are IPSec/UDP (NAT/PAT), so that's not what's causing the problem. In fact the only difference between the two profiles is the host IP address.

[1]Player
29-01-2007, 05:35 PM
Could this be an issue with ipsec nat-traversal? hmm

krakan
29-01-2007, 09:42 PM
Player;283310']Could this be an issue with ipsec nat-traversal? hmm

With respect to what? (Excuse my ignorance!)

[1]Player
30-01-2007, 04:40 PM
when ipsec vpn equipment first came out the support for NAT was non-existant.

On the concentrator side support for nat traversal was slowly added through software patches, and some NAT devices also added botched work arounds to help it work. For example, you might have found the first ipsec session through a NAT device worked.

I'm wondering if your end device supports nat-t.

Of course... it could also be a t-mobile network "feature"