<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 2811 ISR behind Cisco PIX 515 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338769#M839737</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have had issues in the past were a blanket layer 3 IP acl just does not allow traffic thru.  When replaced with a more specific layer 4 config, everything works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jun 2009 14:29:06 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2009-06-25T14:29:06Z</dc:date>
    <item>
      <title>Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338758#M839726</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to build a site-to-site vpn between two locations using Cisco 2811 ISR routers. At site A the 2811 router is behind a Cisco ASA with version 7.2 and at site B the Cisco 2811 router is behind a Cisco PIX 515 with version 6.3. The tunnel does not seems to come up, all the vpn configurations are fine, but the tunnel fails in Phase 2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the same configuration, the tunnel is working fine between Site A and Site C, where both the Cisco 2811 ISR routers are behind Cisco ASA 5510 with version 7.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Cisco ASA 5510 and Cisco PIX 515, we have only done a static NAT and opened the inbound &amp;amp; outbound ip traffic for the head-end ip addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any compatibility issues between Cisco ISR routers with Cisco PIX 515 with version 6.3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338758#M839726</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2019-03-11T15:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338759#M839727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The cause is you are not permitting Protocol 50 thru the firewall, to establish IPSEC Phase 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 08:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338759#M839727</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T08:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338760#M839728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have allowed IP traffic both inbound and outbound on the firewalls at both sites. With the configuration the tunnel between Site A and Site C working fine. But not between Site A - Site B or Site C - Site B. The only difference Site B has a Cisco PIX 515 with 6.3 version and other two sites have a ASA 5510 with 7.2 version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I was suspecting if PIX requires any additional configuration or PIX and ISR routers not compatible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 09:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338760#M839728</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2009-06-25T09:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338761#M839729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arabinda,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have an ACL that allows "IP" thru - this also permit TCP/UDP.  Phase 1 of a VPN tunnel is ISAKMP - typically UDP port 500 - so this will work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ESP which is Phase 2 of the VPN uses Protocol number 50 - you you also need to add to the ACL the permit for protocol 50-ESP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you have done this, Phase 2 will complete - as long as all config matches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 09:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338761#M839729</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T09:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338762#M839730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Andrews,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried that, I added another acl allowing ESP both on inbound and outbound on both firewalls, still does not works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attached is a log file hope that may throw some light to what the issue is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 09:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338762#M839730</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2009-06-25T09:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338763#M839731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Post the config of the ACL - remove sensitive information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 10:21:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338763#M839731</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T10:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338764#M839732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the ACL which is applied on the PIX where the static NAT is done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-acl extended permit ip host 12.x.x.x host 12.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-acl extended permit esp host 12.x.x.x host 12.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-grooup outside-acl in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside-acl extended permit ip host 10.x.x.x any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside-acl extended permit host 10.x.x.x esp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside-acl in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.x.x.x 10.x.x.x mask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Similar is the config on the other side ASA box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:10:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338764#M839732</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2009-06-25T14:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338765#M839733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Change to:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-acl extended permit udp host 12.x.x.x host 12.x.x.x eq 500&lt;/P&gt;&lt;P&gt;access-list outside-acl extended permit udp host 12.x.x.x host 12.x.x.x eq 4500&lt;/P&gt;&lt;P&gt;access-list outside-acl extended permit esp host 12.x.x.x host 12.x.x.x &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no need for the entries on the inside-acl, they should be removed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338765#M839733</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T14:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338766#M839734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay Thank you Andrew, let me try it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ACL only applies to PIX 515? Since with the ACL mentiioned earlier I have VPN working between two sites perfectly difference is, there we have ASA 5510 as the NAT device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338766#M839734</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2009-06-25T14:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338767#M839735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to disagree with you on this.  Arabindas has this in the ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-acl extended permit ip host 12.x.x.x host 12.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should cover everything, including udp/500, udp-4500 and ESP, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why does he have to modify the ACL?  One other thing, you should put "log" at the end of the ACL so that you can see whether it is permitted or dennied on the syslog server or logging buffer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338767#M839735</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-06-25T14:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338768#M839736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrews, even I modified the ACL as per recommended, still no luck. I also guess IP allowed should take care of both UDP and TCP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dst             src             state          conn-id slot status&lt;/P&gt;&lt;P&gt;12.x.x.x    10.x.x.x      MM_NO_STATE          0    0 ACTIVE &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338768#M839736</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2009-06-25T14:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338769#M839737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have had issues in the past were a blanket layer 3 IP acl just does not allow traffic thru.  When replaced with a more specific layer 4 config, everything works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338769#M839737</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T14:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338770#M839738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the debug on the ISR, is anything getting thru to it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the debug at the remote end, is the ISR initiating the VPN, is the remote end Firewall allowing the traffic thru?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More debug is required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338770#M839738</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T14:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338771#M839739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"I have had issues in the past were a blanket layer 3 IP acl just does not allow traffic thru."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you telling me that if you have "permit ip any any log" in the ACL, it still may not work unless you have a more specific layer 4 config?  That's the first time I have heard of this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338771#M839739</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-06-25T14:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338772#M839740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes - I have had that issue on PIX506E, 515 &amp;amp; 515E running 6.3.x &amp;amp; 7.0.x code in the past.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:50:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338772#M839740</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T14:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338773#M839741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just now I captured the logs from both the ISR routers simultaneously.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site A refers to logs from ISR router behind an ASA and Site C refers to ISR router Cisco PIX 515.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338773#M839741</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2009-06-25T14:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338774#M839742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the logs, it appears that you are blocking the response from C to A.  Check the config on the 515.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338774#M839742</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T14:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338775#M839743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Yes - I have had that issue on PIX506E, 515 &amp;amp; 515E running 6.3.x &amp;amp; 7.0.x code in the past."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have the exact version of 6.3.x and 7.0.x that you had issues with?  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 15:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338775#M839743</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-06-25T15:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338776#M839744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot remember - I encountered these issues in 2007&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 16:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338776#M839744</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-25T16:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2811 ISR behind Cisco PIX 515</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338777#M839745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry since I work in India Time zone, it was quite late yesterday and could not respond. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have allowed IP traffic, so now I do not know what is blocking on PIX side. Also the version of the code on PIX is 6.3(3)132.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Arabinda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2009 03:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2811-isr-behind-cisco-pix-515/m-p/1338777#M839745</guid>
      <dc:creator>arabindas</dc:creator>
      <dc:date>2009-06-26T03:32:47Z</dc:date>
    </item>
  </channel>
</rss>

