cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1243
Views
0
Helpful
0
Comments
TCC_2
Level 10
Level 10

Core issue

The fixup protocol esp-ike command enables Port Address Translation (PAT) for Encapsulating Security Payload (ESP), single tunnel.

The fixup protocol esp-ike command is disabled by default. If a fixup protocol esp-ike command is issued, the fixup is turned on, and the PIX Firewall preserves the source port of the Internet Key Exchange (IKE). It also creates a PAT translation for ESP traffic. Additionally, if the esp-ike fixup is on, Internet Security Association and Key Management Protocol (ISAKMP) cannot be enabled on any interface.

Resolution

In order to resolve the issue, disable the fixup protocol esp-ike command and make sure that there is static translation on the PIX for the VPN tunnel endpoint behind the PIX.

Problem Type

Troubleshoot software feature

Product Family

Firewall - PIX 500 series

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: