I have a 515 PIX that was initially setup to allow ~120 vpn connections using Dynamic IPSEC with a common ISAKMP key. We are finding that this doesn't work very well due to the PIX 515 confusing it's Destination IP address while the VPN is connected, rendering that location's VPN unusable.
I'm going to add 80 more VPN connections to my 515 PIX and I'm wanting to use EasyVPN instead of Dynamic IPSEC tunnels just for the 80 new locations. The remote locations will have PIX 501s. EasyVPN works great on my test equipment, but when implemented on our current 515 which is currently running Dynamic IPSEC tunnels, EasyVPN does not work. I recieve an error when I do a "debug crypto isakmp":
"ISAKMP (0): atts are not acceptable. Next payload is 0"
Does anyone know if it's possible to run both VPN authentications concurrently?
Shon
Network Administrator
I'm going to add 80 more VPN connections to my 515 PIX and I'm wanting to use EasyVPN instead of Dynamic IPSEC tunnels just for the 80 new locations. The remote locations will have PIX 501s. EasyVPN works great on my test equipment, but when implemented on our current 515 which is currently running Dynamic IPSEC tunnels, EasyVPN does not work. I recieve an error when I do a "debug crypto isakmp":
"ISAKMP (0): atts are not acceptable. Next payload is 0"
Does anyone know if it's possible to run both VPN authentications concurrently?
Shon
Network Administrator