I have a network with a 3005 concentrator and PIX 515 in parallel. Thre is a router on the public side of the PIX/3305 that also connects to my ISP. There is another oruter in front of the PIX/3305 that acts as my internal network default gateway and directs LAN-to LAN traffic to the 3005. my problem is when I try to use a software VPN (to a totally seperate network) from the internal network, I cannot connect. If I capture traffic to the other network on my PIX, it fails as follows: 192.168.x.x > 216.x.x.x icmp: 192.168.x.x UDP port 500 unreachable. I am allowing udp 500 traffic through an ACL, so i don't understand why this is happening. Is the ISAKMP traffic going out the concentrator? Can I prevent this? Any help is appreciated!!!