cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
344
Views
0
Helpful
3
Replies

3Com OfficeConnect Secure Gateway to PIX515 VPN

iikendall
Level 1
Level 1

I am trying to get one of these 3Com boxes to create a SA with a PIX, using DES (may go to 3-DES if I can get this bit working), but get the message in debug - IPSEC(validate_proposal): invalid local address a.b.c.d - where a.b.c.d is the outside address of the PIX.

I am not sure if the transform set is correct, as the 3Com has almost no useful information with it. I think I have tried all the combinations, but still draw a blank.

Any help gratefully received.

3 Replies 3

kdurrett
Level 3
Level 3

Invalid local address usually means that the crypto map isnt applied to the interface. Look for "crypto map mymap interface outside" for example. Post your pix config and debugs if you can. But i've seen the same error when its configured correctly, which usually a reload of the pix, after you do a wr mem of course, will solve that issue.

Kurtis Durrett

Kurtis,

Apologies for not replying earlier. You were quite correct, when I cut and pasted the config from another customer's, I managed to omit the line that applies the cryto map, but couldn't see this when I checked the config.

Thanks for the help.

Iain

afakhan
Level 4
Level 4

Hi,

Please make sure that your crypto ACLs on the router, and local/remote proxy IDs on the 3COM are symmetrical.

Thanks,

Afaq

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: