Cisco IPsec Easy VPN Configuration

Hello Dinesh

There are a couple of things that you should keep in mind as you troubleshoot this. First of all, with EasyVPN you don’t need to configure an ACL, so all traffic is permitted, so this is not where your problem lies. This is different than a site-to-site VPN where you configure an ACL to define the traffic to encrypt. It’s possible to use an ACL to restrict traffic with EasyVPN but you haven’t done this so you’re OK here.

Now you’re unable to ping from the VPN client to the web server, but you don’t know up to where the packet is going. Check to see how far the packet gets, to see if it actually reaches the web server and fails on the return, or if it never reaches it at all. Check all devices in between to see where the packet fails.

Finally, check your NAT rules. Specifically when you ping, check your translations and make sure that the address isn’t being translated in error before trying to be sent.

I hope this helps you in your troubleshooting, and points you in the right direction. Let us know how it goes!!

I hope this has been helpful!

Laz