I've the following VPN ipsec 3des config in our pix 515. The VPN connection PIX-2-PIX and Client-2-PIX seems to work ok but since i've put these config in our PIX we have problems witch our internet/e-mail access. Can anyone please tell me what is wrong in my VPN config?
access-list 101 permit ip 92.0.0.0 255.0.0.0 192.168.49.0 255.255.255.0
access-list 101 permit ip 92.0.0.0 255.255.255.0 80.0.0.0 255.0.0.0
access-list nonat permit ip 92.0.0.0 255.0.0.0 192.168.49.0 255.255.255.0
access-list nonat permit ip 92.0.0.0 255.255.255.0 80.0.0.0 255.0.0.0
ip local pool bigpool 92.0.3.1-92.0.3.150
nat (inside) 0 access-list nonat
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server AuthIn protocol tacacs+
sysopt connection permit-ipsec
no sysopt route dnat
crypto ipsec transform-set myset esp-3des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set myset
crypto map mymap 10 ipsec-isakmp
crypto map mymap 10 match address 101
crypto map mymap 10 set peer YYY.YYY.YYY.149
crypto map mymap 10 set transform-set myset
crypto map mymap 20 ipsec-isakmp dynamic dynmap
crypto map mymap client authentication AuthIn
crypto map mymap interface outside
isakmp enable outside
isakmp key ******** address YYY.YYY.YYY.149 netmask 255.255.255.255
isakmp key ******** address 0.0.0.0 netmask 0.0.0.0
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
vpngroup vpn3000 address-pool bigpool
vpngroup vpn3000 idle-time 1800
access-list 101 permit ip 92.0.0.0 255.0.0.0 192.168.49.0 255.255.255.0
access-list 101 permit ip 92.0.0.0 255.255.255.0 80.0.0.0 255.0.0.0
access-list nonat permit ip 92.0.0.0 255.0.0.0 192.168.49.0 255.255.255.0
access-list nonat permit ip 92.0.0.0 255.255.255.0 80.0.0.0 255.0.0.0
ip local pool bigpool 92.0.3.1-92.0.3.150
nat (inside) 0 access-list nonat
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server AuthIn protocol tacacs+
sysopt connection permit-ipsec
no sysopt route dnat
crypto ipsec transform-set myset esp-3des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set myset
crypto map mymap 10 ipsec-isakmp
crypto map mymap 10 match address 101
crypto map mymap 10 set peer YYY.YYY.YYY.149
crypto map mymap 10 set transform-set myset
crypto map mymap 20 ipsec-isakmp dynamic dynmap
crypto map mymap client authentication AuthIn
crypto map mymap interface outside
isakmp enable outside
isakmp key ******** address YYY.YYY.YYY.149 netmask 255.255.255.255
isakmp key ******** address 0.0.0.0 netmask 0.0.0.0
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
vpngroup vpn3000 address-pool bigpool
vpngroup vpn3000 idle-time 1800