Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Nortel VPN Thru PIX 501 2

Status
Not open for further replies.

fluxeon

MIS
Feb 17, 2004
3
0
0
US
Okay I am lost, I have tried all things listed in this post, the fixup esp does not work and setting access-list to open up ports and other misc access-list still will not allow the VPN client to pass thru the pix properly. The only way it works is if I set a static xlate to the outside to the inside address, but then I lose all other connections on the pix. I am using 6.3.3, any tips on what is going on? Thanks in advance.
 
Add these lines:

access-list contiv permit udp any any eq isakmp
access-list contiv permit ah any any
access-list contiv permit esp any any
access-group contiv in interface outside
fixup protocol esp-ike


That should do it. You will need version 6.3x for this to work.

-Joe
 
I found a similar situation, and this worked without using the fixup protocol esp-ike in version 6.3(4).
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top