<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bluefire VPN Client to PIX in VPN</title>
    <link>https://community.cisco.com/t5/vpn/bluefire-vpn-client-to-pix/m-p/635733#M193303</link>
    <description>&lt;P&gt;We have a few PDA's on trial and am trying the bluefire VPN client. This did work for a while but now it won't connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing I can see in a isakmp debug is the following -:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): sending NAT-T vendor ID - rev 2 &amp;amp; 3&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): constructed HIS NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): constructed MINE NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected port floating&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block:src:*.*.*.*, dest:FIREWALL spt:10587 dpt:4500&lt;/P&gt;&lt;P&gt;OAK_AG exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing HASH payload. message ID = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NOTIFY payload 24578 protocol 1&lt;/P&gt;&lt;P&gt;        spi 0, message ID = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing notify INITIAL_CONTACT&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d1fcf4, conn_id = 0&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d5ec4c, conn_id = 0&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d30744, conn_id = 0&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d2734c, conn_id = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected NAT-D payload&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): recalc my hash for NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): NAT match MINE hash&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected NAT-D payload&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): recalc his hash for NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): NAT does not match HIS hash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does 'NAT does not match HIS hash' mean?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 22:51:12 GMT</pubDate>
    <dc:creator>siiiilky</dc:creator>
    <dc:date>2020-02-21T22:51:12Z</dc:date>
    <item>
      <title>Bluefire VPN Client to PIX</title>
      <link>https://community.cisco.com/t5/vpn/bluefire-vpn-client-to-pix/m-p/635733#M193303</link>
      <description>&lt;P&gt;We have a few PDA's on trial and am trying the bluefire VPN client. This did work for a while but now it won't connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing I can see in a isakmp debug is the following -:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): sending NAT-T vendor ID - rev 2 &amp;amp; 3&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): constructed HIS NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): constructed MINE NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected port floating&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block:src:*.*.*.*, dest:FIREWALL spt:10587 dpt:4500&lt;/P&gt;&lt;P&gt;OAK_AG exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing HASH payload. message ID = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NOTIFY payload 24578 protocol 1&lt;/P&gt;&lt;P&gt;        spi 0, message ID = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing notify INITIAL_CONTACT&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d1fcf4, conn_id = 0&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d5ec4c, conn_id = 0&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d30744, conn_id = 0&lt;/P&gt;&lt;P&gt;ISADB: reaper checking SA 0x3d2734c, conn_id = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected NAT-D payload&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): recalc my hash for NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): NAT match MINE hash&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected NAT-D payload&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): recalc his hash for NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): NAT does not match HIS hash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does 'NAT does not match HIS hash' mean?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 22:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/bluefire-vpn-client-to-pix/m-p/635733#M193303</guid>
      <dc:creator>siiiilky</dc:creator>
      <dc:date>2020-02-21T22:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Bluefire VPN Client to PIX</title>
      <link>https://community.cisco.com/t5/vpn/bluefire-vpn-client-to-pix/m-p/635734#M193305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The hashing value that was calculated between the devices did not match after the NAT-D detection was done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the client connecting from behind a firewall or a NAT device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, do you have NAT-T enabled on the VPN headend device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gilbert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2007 21:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/bluefire-vpn-client-to-pix/m-p/635734#M193305</guid>
      <dc:creator>ggilbert</dc:creator>
      <dc:date>2007-02-05T21:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Bluefire VPN Client to PIX</title>
      <link>https://community.cisco.com/t5/vpn/bluefire-vpn-client-to-pix/m-p/635735#M193309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange, just re-installed the software on the handheld and it is working fine now!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2007 09:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/bluefire-vpn-client-to-pix/m-p/635735#M193309</guid>
      <dc:creator>siiiilky</dc:creator>
      <dc:date>2007-02-06T09:24:14Z</dc:date>
    </item>
  </channel>
</rss>

