Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

checkpoint vpn connection through pix 506

I'm trying to configure a pix 506 to let checkpoint vpn clients initiate vpn connection from inside network. Here is the setup.

vpn client --> pix(PAT) --> internet --> vpn server

The vpn connection can establish successfully. However, no internal resources can be reached nor pinged.

I tried "isakmp nat-traversal" and "fixup protocol esp-ike" but still not work. Can someone give a hint?

Also, does it really work if I use PAT but not NAT?

Thanks in advance.

Daniel

1 REPLY
Cisco Employee

Re: checkpoint vpn connection through pix 506

Daniel.

Can you verify the PIX logs and see if it reports some denied packets?

On your ACL, do you have ESP open for the checkpoint server?

Logs from the PIX while you are trying to access resources on the checkpoint side would help.

- Rate it, if it helps -

99
Views
0
Helpful
1
Replies