Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

problem with vpn pass through

I have a pix 515E and am trying to vpn from inside my network to an outside company. I use the cisco vpn client however when i go to connect to get an error "received malformed message or negotion no longer active"

i have added a network object group in our pix config allowing access to the remote firewall but i still seem to get the error. Any help would be much appreciated.



Re: problem with vpn pass through

Have you tryed with the fixup protocol esp-ike ?

PIX Firewall Version 6.3 provides improved support for application inspection of Encapsulating Security Payload (ESP) and for using IPSec with NAT.

ESP is an IPSec protocol that provides data confidentiality, data integrity, and protection services, optional data origin authentication, and anti-replay services. ESP encapsulates the data to be protected.

However, because ESP packets do not identify the ports that are involved, PAT is performed by assigning port 0 (zero). Only one ESP tunnel is supported at a time. Also, when the PIX Firewall has this feature enabled, it cannot terminate VPN tunnels in relation to other IPSec peers.

Application inspection of ESP traffic is disabled by default. To enable this feature, enter the following command:

fixup protocol esp-ike

When this feature is enabled, PIX Firewall preserves the IKE source port. Support is not provided for the following:

•ESP tunnel serialization

•SPI matching

•Recording of SPIs for each ESP connection

Configuring an IPSec Tunnel through a Firewall with NAT:



Community Member

Re: problem with vpn pass through

How do you do this configuration using PDM?

Not knowing all the technical details, I find it hard to translate the PIX command solutions into PDM use.

Community Member

Re: problem with vpn pass through

I get the message "PAT for ESP cannot be enabled since ISAKMP is enabled. Please correct your conf

iguration and re-issue the command!


all i am trying to do is a vpn pass through the pix

CreatePlease to create content