In order to pass IPSec VPN connections through WinProxy, you will need to have some necessary information from your Network Administrator. You will need to contact them and ask what passwords and usernames are necessary for your VPN application.

This is the initial screen for the Cisco 3000 VPN Client. First you will need to click the ‘New’ button and enter in the necessary information from your Network Administrator.

We connected to the VPN server using the option ‘Allow IPSec through NAT mode’ both checked and unchecked.

In this section the Group Access Information is NOT the username and password! This is actually where you enter in the information to make the initial connection to the VPN server. Once this information is entered (and you specify the IP address to connect to), you can begin the connection process.

This is the first screen you will see after clicking ‘Connect’, followed by the screen below:

At this point in time, you should get the username and password login screen:

Enter in your username and password for the VPN server, then click ‘OK’. Once again you will get the ‘Negotiating security profiles’ window. If the username and password match what is on the VPN server, then you will get a confirmation window that looks like this:

Followed by:

At this point you are connected to the VPN gateway. The last thing for you to do is to log onto the network when prompted:

Once verified, your VPN connection is completed.
Once completing these steps, some customers have encountered another issue. They can log in, but cannot reach anywhere else on the LAN they are connected to. To resolve this issue, changes have to be made on the VPN SERVER box, NOT the client, and NOT WinProxy. Changes to the settings are made in the VPN 3000 Concentrator setup, which has a web interface. The first adjustment is in:
Configuration > User Management > Base Group.
There is setting called NAT. Turn it off. Check to see if the connection works. If it still does not work, the next change is in:
Configuration > System > Address Management > Assignment
Set it to "Use Address From Authentication Server", "Use Address Pools" or both. Do not set it to "Use DHCP" or "Use Client Address". Once this is done try the connection again. At this point it should work, and you should be able to connect.


