03-11-2006 07:18 AM - edited 02-21-2020 02:18 PM
Is it necessary to always enable "no-xauth no-config-mode" after the isakmp key statement for s2s VPN if you are also running EZVPN with Extended Authentication?
03-12-2006 11:53 PM
Hi
No, it is not necessary, s2s vpn works fine with isakmp key and address info only.
regards
aashish C
03-13-2006 06:48 AM
Thanks for answering. Turns out the remote end device was a non Cisco VPN endpoint for the s2s vpn. I created another site to site vpn to another location of ours which was another pix and I didnt have this problem. So it seems it may be necessary for non Cisco devices to enable this feature.
03-13-2006 03:40 PM
not too sure about lan-lan and ezvpn on the same pix. i do actually have the keyword.
nonetheless, i'm pretty sure the keyword is required for lan-lan and remote vpn on the same pix.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide