I'm trying to configure a pix 506 to let checkpoint vpn clients initiate vpn connection from inside network. Here is the setup.
vpn client --> pix(PAT) --> internet --> vpn server
The vpn connection can establish successfully. However, no internal resources can be reached nor pinged.
I tried "isakmp nat-traversal" and "fixup protocol esp-ike" but still not work. Can someone give a hint?
Also, does it really work if I use PAT but not NAT?
Thanks in advance.
Daniel