Config of the PIX is massive - we have a very large number of remote sites (as I mentioned, the remote sites are using Cisco 837s without issue) so there's probably not much point posting it's entire config.
So, I *think* the config attached is everything of relevance to this connection on the PIX:
For testing purposes, I'm using a dynamic Public IP address on the 2811 - I have this working from the same ADSL connection using a Cisco 837.
I have also attached the config of the Cisco 2811 with IP addresses etc removed.
Essentially, I have based the config on the Cisco 2811 as much as I can on a working Cisco 837 config. So what is required on a Cisco 2811 site-to-site IPSEC VPN connection with a PIX which wasn't required on the Cisco 837?
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
[toc:faq]Introduction:This document describes details on how NAT-T
works.Background:ESP encrypts all critical information, encapsulating
the entire inner TCP/UDP datagram within an ESP header. ESP is an IP
protocol in the same sense that TCP and UDP are I...