Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

VPN through a PIX 515

I installed a PIX 515 and now have a user that cannot access a site via VPN that worked previously. What configuration changes would I need to allow outgoing VPN traffic only?

Thanks, Joe

2 REPLIES
Cisco Employee

Re: VPN through a PIX 515

normally you would allow udp/500 for isakmp

also protocol 50 for esp or protocol 51 for ah depending on what transform you are using (or both).

New Member

Re: VPN through a PIX 515

Are you using NAT? If the inside user is launching the VPN client from their desktop computer and the PIX is performing address translation then the SA will be broken and the VPN session will fail. You cannot alter a secure encapsulated packet and expect it to work.

106
Views
0
Helpful
2
Replies
CreatePlease to create content