cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
371
Views
3
Helpful
3
Replies

PIX 6.3 portmap translation

vg200
Level 1
Level 1

I have a pix 515 running dhcp on the outside interface. When a vpn client connects from behind the pix it generates error "protmap translation creation failed for protocol 50 src inside <host> to dst <host>.

3 Replies 3

s.surani
Level 1
Level 1

I think this has to do something with your patting. the work around for this is to deny patting from your lan to the vpn client.

mhussein
Level 4
Level 4

It seems - as Salim mentioned above - that you are using a PAT address. For IPSec vpn clients you need to configure a static ip address for the client and allow the remote vpn gateway to reply on ESP (protocol 50).

e.g.

static (inside,outside) y.y.y.y z.z.z.z netmask 255.255.255.255 0 0

access-list acl_in permit esp host x.x.x.x host y.y.y.y

where y.y.y.y is the "outside or public" ip of the host, and x.x.x.x is the remote vpn gateway ip address.

HTH,

Mustafa

Thanks for the help. The issue was resolved by adding a acl for esp to the outside interface access-list.

Review Cisco Networking products for a $25 gift card