cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
388
Views
0
Helpful
2
Replies

Symantec VPN Appliance 100 to PIX?

tonyc
Level 1
Level 1

Has anyone had any luck in getting a gateway-to-gateway VPN up between a PIX 515 6.0.1 and a Symantec VPN Appliance 100 (Nexland OEM)?

We've tried IKE pre-shared DES ESP MD5 with no luck.

2 Replies 2

ciscomoderator
Community Manager
Community Manager

Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center (http://www.cisco.com/tac) or speak with a TAC engineer. You can open a TAC case online at http://www.cisco.com/tac/caseopen

If anyone else in the forum has some advice, please reply to this thread.

Thank you for posting.

Thanks, but I already contacted TAC, and ended up solving this issue (and all my other ones) before they could respond.

The short answer is if you are using this device with a PIX to make a Lan-to-Lan tunnel, and you are using DES MD5 in pre-share mode for key exchange, then you have to set a ISAKMP policy on the PIX that uses "Group 1" compression rather than Group 2 (which I believe is the default.