<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515 running 6.2(1) code - help required. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479670#M534244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the delay in responding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For NAT-T to work properly you need to define it on the PIX that you're connecting to, which would be the one running 6.2(1).  Unfortunately, as you've figured out, NAT-T was not supported in 6.2 code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you can do is allow the PIX you're going thru (the one running 6.3(4)) to properly open up holes for the ESP traffic, then you shouldn't need to change anything on the 6.2(1) PIX.  The following command on the 6.3(4) PIX will do that for you:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;fixup protocol esp-ike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Aug 2005 03:08:43 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2005-08-16T03:08:43Z</dc:date>
    <item>
      <title>PIX 515 running 6.2(1) code - help required.</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479669#M534242</link>
      <description>&lt;P&gt;I have setup VPN client access to my PIX 515 running version 6.2 (1), now my problem is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I use a PSTN dial-up connection from my laptop and then run the VPN client, I can connect to my PIX &amp;#150; no problem and also can access the internal network. But when I try to connect to the PIX using the same VPN client from behind another PIX (running version 6.3(4)) I can not connect, I get a &amp;#145;peer not responding message on the VPN client&amp;#146;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please explain what I am missing here, or do I need to enable some command on the PIX which is running 6.2(1) code?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have NAT-T enabled on my PIX with 6.3(4) code but can not find any references to NAT-T for PIX with 6.2(1) code!! &amp;#150;  could this be the problem, if so is there any solutions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS. I am using VPN client version 4.0.1 (Rel)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really need this up and running ASAP so any help will be much appreciated also, I can not upgrade the 515 to 6.3(4) as customer does not want to!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for you assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479669#M534242</guid>
      <dc:creator>OHITS-OPS</dc:creator>
      <dc:date>2020-02-21T08:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 running 6.2(1) code - help required.</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479670#M534244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the delay in responding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For NAT-T to work properly you need to define it on the PIX that you're connecting to, which would be the one running 6.2(1).  Unfortunately, as you've figured out, NAT-T was not supported in 6.2 code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you can do is allow the PIX you're going thru (the one running 6.3(4)) to properly open up holes for the ESP traffic, then you shouldn't need to change anything on the 6.2(1) PIX.  The following command on the 6.3(4) PIX will do that for you:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;fixup protocol esp-ike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2005 03:08:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479670#M534244</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2005-08-16T03:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 running 6.2(1) code - help required.</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479671#M534246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case we can have just one ESP connection through the 6.3(4) PIX at a time, does it true?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2005 04:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479671#M534246</guid>
      <dc:creator>mehrdad</dc:creator>
      <dc:date>2005-08-16T04:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 running 6.2(1) code - help required.</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479672#M534249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glenn - many thanks for your response, when I tried to configure the fixup for esp-ike on the PIX that is running 6.3(4), I got the following message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW_1_UK(config)# fixup protocol esp-ike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAT for ESP cannot be enabled since ISAKMP is enabled.  Please correct your configuration&lt;/P&gt;&lt;P&gt;and re-issue the command!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have several site-to-site VPN tunnels terminating on this firewall, is there anything I could setup on the PIX that is running 6.2(1) or even the 6.3(4)??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your suggestions/help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2005 06:23:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479672#M534249</guid>
      <dc:creator>OHITS-OPS</dc:creator>
      <dc:date>2005-08-16T06:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 running 6.2(1) code - help required.</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479673#M534251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"However, because ESP packets do not identify the ports that are involved, PAT is performed by assigning port 0 (zero). Only one ESP tunnel is supported at a time. Also, when the PIX Firewall has this feature enabled, it cannot terminate VPN tunnels in relation to other IPSec peers"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/fixup.htm#wp1094669" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/fixup.htm#wp1094669&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2005 06:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-running-6-2-1-code-help-required/m-p/479673#M534251</guid>
      <dc:creator>mehrdad</dc:creator>
      <dc:date>2005-08-16T06:34:40Z</dc:date>
    </item>
  </channel>
</rss>

