Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX to Vigor 2600G VPN NAT-T tunnel problem

Status
Not open for further replies.

seggsy

IS-IT--Management
Aug 24, 2001
5
0
0
GB
I have configured a Vigor 2600G router to create a VPN tunnel to a PIX 506 firewall (OS 6.3(3)). The PIX also has VPN Clients terminating there. The tunnel works whilst I have NAT-T disabled on the PIX. When I enable NAT-T which I need for my VPN Client users the tunnel fails.

Does anyone have experience of the above problem. I would like to be able to make an adjustment on the Vigor to to resolve this problem. I have looked on the Draytek website but information is scant.

Thanks for any help

Seggsy
 
Since you have both LAN-to-LAN and VPN client tunnels, make sure your isakmp key for the LAN-to-LAN includes the keywords no-xauth no-config-mode:

isakmp key ******** address VV.XX.YY.ZZ no-xauth no-config-mode
 
Apologies, I forgot to mention that I already have a tunnel established to another PIX which works fine without having to disable NAT-T. It is only to the Vigor that I experience this problem.

With respect to the no-xauth and no-config-mode on the isakmp key, I do have those entries.

Seggsy
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top