Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 515 to Linksys BEFSX41 VPN Site to Site

Status
Not open for further replies.

rlyj

IS-IT--Management
Jun 6, 2003
4
CA
Hi everyone,

I am trying to create a VPN tunnel between a PIX 515 and Linksys BEFSX41 router. The connection can be established successfully and I can access the machines in BEFSX41 network from machines in PIX network, but not the other way around. The only way I can make a machine(A) in BEFSX41 network to access a machine(B) in PIX network is to ping the A from B first. Then B can access A no problem.

Any ideas?

Thank in advance,
Randy
 
Thanks for the reply.

Both devices have the same timeout value (isakmp policy 9 lifetime 3600). The debugging is enabled on PIX but I can't see anything wrong. Any other suggestions?

TIA,
Randy
 
HI.

> Both devices have the same timeout value (isakmp policy 9 lifetime 3600).
This is NOT the only timeout value.
There are other timeout values, you should check them all.

Try the following command at the pix to see the default IPSec timeout values:
show crypto map

Look for:
Security association lifetime: ...........

But also look at the PFS configuration for both peers.

Bye


Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top