cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1107
Views
0
Helpful
0
Comments
TCC_2
Level 10
Level 10

Core issue

The VPN client fails to connect to the PIX firewall and VPN Tunnel is unable to complete the Phase 2 negotiations.

The debug crypto ipsec command shows this error message:

IPSEC(validate_transform_proposal): proxy identities not supported

This issue usually occurs if crypto maps are configured with the PIX Device Manager (PDM), because the PDM generates and adds this entry into the crypto map independently:

crypto dynamic-map  20 match address

Resolution

In order to resolve this issue:

Use the command line in order to remove this entry from the crypto map. Use the no form in front of this entry in order to remove it. For example:

PIX(config)#no crypto dynamic-map  20 match address

Note: It is necessary to remove the crypto map from the outside interface before any changes are made.

Attempts to connect to the VPN client now work.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: