cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
964
Views
0
Helpful
9
Replies

Remote VPN on PIX 515 and Cisco VPN Client ver 4.x and higher.

shivani.sharma
Level 1
Level 1

Hello,

I have PIX 515 setup as Cisco VPN server for Cisco clients. When users connect using Cisco client ver 3.5, they are able to get to the login prompt. But users trying to connect using Cisco client higher than version 3.5 (like ver 4.6) it just times out.

When I look at the debug logs I see PIX trying to send phase 1 packets back, but the client does not see a response.

I am using esp-3des esp-md5-hmac with pre-share.

Does anyone know why I cannot use client version above 3.5??

Thank you.

1 Accepted Solution

Accepted Solutions

Hi,

Please check the below link (release notes for 6.2 (2)) - Section:  Cisco VPN Client Interoperability

http://www.cisco.com/en/US/docs/security/pix/pix62/release/notes/pixrn622.html#wp88393

If you are using windows client it only support 3.x.  You may need IOS upgrade or Linux, Solaris, and Macintosh platforms client to use with 3.5 or higher.

If your client is compatible from the above, then you may need to run 'debug' on PIX to see whats going on when the client requests connection.

hth

MS

View solution in original post

9 Replies 9

mvsheik123
Level 7
Level 7

Hi,

Is PIX is running version 6.2 or higher?

Thanks

MS

PIX is running ver 6.2

Thanks

Hi,

Have you tried with multiple clients PC/laptop with 4.x installed? Also, please  check to see if the response from PIX reaching out to client at all (vpn client gives basic info, but using wireshark or anyother pkt capture may give more info).

Thanks

MS

I have tried using multiple laptops with Client versions higher than 3.5. Since I get response when I try to connect using Cisco Client ver 3.5, I assume I have IP connectivity and nothing is blocking the IPSec packets. But I will do a packet capture on the client and find out exactly if the return packets reach the client when I use verions above 3.5.

ok..I know you confirmed this already.. exact version for IOS is : Cisco PIX Firewall, Version 6.2.2(122) or Version 6.3(1).

Thanks

MS

Its

Cisco PIX Firewall Version 6.2(2)

Thanks

I also did packet capture using both client versions. I see return packets from VPN server when using client 3.5. But when I use ver 4.x or 5.x there is no response back from the PIX. Do you know what could be causing this?

Thank you.

Hi,

Please check the below link (release notes for 6.2 (2)) - Section:  Cisco VPN Client Interoperability

http://www.cisco.com/en/US/docs/security/pix/pix62/release/notes/pixrn622.html#wp88393

If you are using windows client it only support 3.x.  You may need IOS upgrade or Linux, Solaris, and Macintosh platforms client to use with 3.5 or higher.

If your client is compatible from the above, then you may need to run 'debug' on PIX to see whats going on when the client requests connection.

hth

MS

Thank you MS! That is exactly the reason I cannot use client versions above 3.5 on Windows. I was beating around the bushes to find out the issue. Thanks a lot!!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: