<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows VPN Client cannot connect to PIX 6.2(1), Mac VPN Cli in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622382#M1025479</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All you have to do is : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no rypto map pix-map 40 ipsec-isakmp dynamic site-map &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that shud do it !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Feb 2007 18:44:31 GMT</pubDate>
    <dc:creator>kaachary</dc:creator>
    <dc:date>2007-02-20T18:44:31Z</dc:date>
    <item>
      <title>Windows VPN Client cannot connect to PIX 6.2(1), Mac VPN Client can</title>
      <link>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622379#M1025476</link>
      <description>&lt;P&gt;I'm using 4.9.01(0030) for Mac with no problems at all.  I've tried both 3.6.3 (Rel) and 4.8.02.0010 for Windows, but neither of them connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Mac version gives me a username/password prompt, the Windows version gives me nothing.  If I turn off authentication on the PIX, the Mac client connects up fine, while the Windows version does not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone seen this before?  The Mac and the PC are behind the same NAT device with no special rules that could affect the operation of one machine or another.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I might say that my Windows installation is messed up, however I have other people on Windows who are unable to connect using the Windows client either so I think that validates the stability of this particular windows installation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client logs and corresponding PIX debugs for both Windows and Mac clients are attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas are appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX IPSec Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set pix-set esp-des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set client-set esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map client-map 10 set transform-set client-set&lt;/P&gt;&lt;P&gt;crypto dynamic-map client-map 10 set security-association lifetime seconds 1800 kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto dynamic-map site-map 10 set transform-set pix-set&lt;/P&gt;&lt;P&gt;crypto dynamic-map site-map 10 set security-association lifetime seconds 1800 kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto map pix-map 40 ipsec-isakmp dynamic site-map&lt;/P&gt;&lt;P&gt;crypto map pix-map 50 ipsec-isakmp dynamic client-map&lt;/P&gt;&lt;P&gt;crypto map pix-map client authentication partnerauth&lt;/P&gt;&lt;P&gt;crypto map pix-map interface outside&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;isakmp key ******** address 0.0.0.0 netmask 0.0.0.0 &lt;/P&gt;&lt;P&gt;isakmp identity address&lt;/P&gt;&lt;P&gt;isakmp client configuration address-pool local client-dynamic outside&lt;/P&gt;&lt;P&gt;isakmp policy 40 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 40 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 40 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 40 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 40 lifetime 3600&lt;/P&gt;&lt;P&gt;vpngroup apollogroup address-pool client-dynamic&lt;/P&gt;&lt;P&gt;vpngroup apollogroup dns-server 192.168.247.17 192.168.247.1&lt;/P&gt;&lt;P&gt;vpngroup apollogroup split-tunnel acl_no-nat&lt;/P&gt;&lt;P&gt;vpngroup apollogroup idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup apollogroup password ********&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622379#M1025476</guid>
      <dc:creator>jlixfeld</dc:creator>
      <dc:date>2019-03-11T09:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Windows VPN Client cannot connect to PIX 6.2(1), Mac VPN Cli</title>
      <link>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622380#M1025477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Client for Windows does not support DES with SHA combination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set pix-set esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto map pix-map 40 ipsec-isakmp dynamic site-map &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change the transform set, and you will be good to go !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Please rate the post if it helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 18:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622380#M1025477</guid>
      <dc:creator>kaachary</dc:creator>
      <dc:date>2007-02-20T18:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Windows VPN Client cannot connect to PIX 6.2(1), Mac VPN Cli</title>
      <link>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622381#M1025478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But it does support 3des/md5, right?  That transform-set is referenced at sequence 50 which should be called after sequence 40, regardless as to whether or not an unsupported combination is found in sequence, 50?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 18:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622381#M1025478</guid>
      <dc:creator>jlixfeld</dc:creator>
      <dc:date>2007-02-20T18:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows VPN Client cannot connect to PIX 6.2(1), Mac VPN Cli</title>
      <link>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622382#M1025479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All you have to do is : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no rypto map pix-map 40 ipsec-isakmp dynamic site-map &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that shud do it !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 18:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622382#M1025479</guid>
      <dc:creator>kaachary</dc:creator>
      <dc:date>2007-02-20T18:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Windows VPN Client cannot connect to PIX 6.2(1), Mac VPN Cli</title>
      <link>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622383#M1025480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course, but then my site-to-site VPNs break &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  I need them both to work (and I'd like to avoid having to reconfigure the site-to-site VPNs if possible).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 18:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622383#M1025480</guid>
      <dc:creator>jlixfeld</dc:creator>
      <dc:date>2007-02-20T18:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Windows VPN Client cannot connect to PIX 6.2(1), Mac VPN Cli</title>
      <link>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622384#M1025481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You dont need all the redundant statements there, to make your S2S and Vpn clients to work, just remove the following statements by doing :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no crypto map pix-map 40 ipsec-isakmp dynamic site-map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then add :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map client-map 10 set transform-set client-set pix-set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That wud take care of client as well as S2S conenctions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 19:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/windows-vpn-client-cannot-connect-to-pix-6-2-1-mac-vpn-client/m-p/622384#M1025481</guid>
      <dc:creator>kaachary</dc:creator>
      <dc:date>2007-02-20T19:39:42Z</dc:date>
    </item>
  </channel>
</rss>

