Troubleshooting Cisco VPN Pass Through

If trouble is encountered when attempting a connection from an internal Cisco VPN client to an external host, (e.g. a workstation with the Cisco client is trying to get out through pfSense® software to connect to a remote site), then try the following.


  • In the Cisco VPN client software, Modify the connection and turn off transparent tunneling completely in the Transport tab.

  • In the pfSense software GUI, under Firewall > NAT on the Outbound tab:

    • Enable Manual Outbound NAT.

    • Remove any NAT rules that perform static port NAT on udp/500.