Cisco Support Community
Community Member

3005 isakmp return traffic via inside interface

I have a 3005 in parallel with pix 515. Both inside interfaces connect to internal switch. From remote, attempt to establish vpn client connection to 3005. The attempt times out, event log sometimes shows that unencrypted packets were received. I noticed on pc software firewall that an address belonging to the ip address pool on pix was attempting connect to my pc on port 500. It appears that the 3005 is receiving the connection request via the public interface and attempting to respond via the inside interface, through the pix and back to the remote pc. Everything seems normal as far as the configuration goes. This one definitely baffles me. I am running the latest image on the 3005. Anyone else experience something similar?


Re: 3005 isakmp return traffic via inside interface

What do you routes look like on the 3005? any chance it is configured to use the pix as its default gateway?

Community Member

Re: 3005 isakmp return traffic via inside interface

The default route on the 3005 points to the border router on the public subnet.

CreatePlease to create content