I have an issue with a VPN connection to a customer firewall. Our end is dual ASA 5520s running in active/passive mode, while the far end is a Pix 506 running 6.3 SW.
When testing failover using hard ASA resets, sometimes the VPN breaks and the Pix shows anti-replay check failures ? things have got out of sequence and the Pix is rightfully dropping the packets.
The customer doesn?t like this and I'm looking for a solution.
On IOS, there is a new feature (http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080455ad4.html)
That can expand the anti-replay window to 1024 packets from 64 default.
The question is is there anything similar for Pix?
Thanks a lot