<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN client behind PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976127#M939937</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"The key here is to look at the configuration &lt;/P&gt;&lt;P&gt;on the VPN concentrator. You need to setup &lt;/P&gt;&lt;P&gt;NAT-T on the VPN concentrator, as follow: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration | Tunneling and Security | IPSec | NAT Transparency &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a check box for "IPSec over NAT-T". &lt;/P&gt;&lt;P&gt;Check that box and it will work. &lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats correct. I understood just the opposite at my first fast look at the question, thats why I rejected to not to NAT-T at PIX side. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Cisco VPN client does not use PPTP protocol"&lt;/P&gt;&lt;P&gt;Thats correct too, but I didnt see any statement about Cisco VPN client, thats why I suggested it. But if I recall correct, client shouldnt have been able to establish connection if it was a PPTP client, without the fixup protocol I mention. So most probably it is Cisco VPN client.&lt;/P&gt;&lt;P&gt;  Setting NAT-T at concentrator will resolve the issue as you mentioned.&lt;/P&gt;&lt;P&gt;  Brian, if still no joy after setting NAT-T in concentrator, we need the config of concentrator.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Apr 2008 15:36:20 GMT</pubDate>
    <dc:creator>Alan Huseyin Kayahan</dc:creator>
    <dc:date>2008-04-02T15:36:20Z</dc:date>
    <item>
      <title>VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976119#M939926</link>
      <description>&lt;P&gt;I have a problem with a vpn client sitting inside a PIX 525 7.2(2). I can connect to the destination concentrator but cannot ping any resources (tested and works fine through little ADSL SOHO kit). After searching here, I added isakmp nat-traversal 20 to the config plus a NAT exemption. I now see clean UDP and TCP traffic in the syslog for this host but I still no replies.....Any help much appreciated as I'm losing hair on this one......&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976119#M939926</guid>
      <dc:creator>molebrian</dc:creator>
      <dc:date>2019-03-11T12:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976120#M939928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian,&lt;/P&gt;&lt;P&gt;  Please attach your sanitized config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 14:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976120#M939928</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-02T14:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976121#M939931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian,&lt;/P&gt;&lt;P&gt;  Please attach your sanitized config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 14:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976121#M939931</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-02T14:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976122#M939932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to enable NAT-T on the VPN concentrator.  You do not need NAT-T on&lt;/P&gt;&lt;P&gt;the Pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 14:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976122#M939932</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-04-02T14:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976123#M939933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Edited... Misunderstood the issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 14:33:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976123#M939933</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-02T14:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976124#M939934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is working for me as we speak.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 14:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976124#M939934</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-04-02T14:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976125#M939935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are right m8, I misunderstood the issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Brian, issue the following command in PIX config&lt;/P&gt;&lt;P&gt;  fixup protocol pptp 1723&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 14:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976125#M939935</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-02T14:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976126#M939936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco VPN client does not use PPTP protocol.&lt;/P&gt;&lt;P&gt;I do not think you need that.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The key here is to look at the configuration&lt;/P&gt;&lt;P&gt;on the VPN concentrator.  You need to setup&lt;/P&gt;&lt;P&gt;NAT-T on the VPN concentrator, as follow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration | Tunneling and Security | IPSec | NAT Transparency&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a check box for "IPSec over NAT-T".&lt;/P&gt;&lt;P&gt;Check that box and it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 15:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976126#M939936</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-04-02T15:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976127#M939937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"The key here is to look at the configuration &lt;/P&gt;&lt;P&gt;on the VPN concentrator. You need to setup &lt;/P&gt;&lt;P&gt;NAT-T on the VPN concentrator, as follow: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration | Tunneling and Security | IPSec | NAT Transparency &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a check box for "IPSec over NAT-T". &lt;/P&gt;&lt;P&gt;Check that box and it will work. &lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats correct. I understood just the opposite at my first fast look at the question, thats why I rejected to not to NAT-T at PIX side. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Cisco VPN client does not use PPTP protocol"&lt;/P&gt;&lt;P&gt;Thats correct too, but I didnt see any statement about Cisco VPN client, thats why I suggested it. But if I recall correct, client shouldnt have been able to establish connection if it was a PPTP client, without the fixup protocol I mention. So most probably it is Cisco VPN client.&lt;/P&gt;&lt;P&gt;  Setting NAT-T at concentrator will resolve the issue as you mentioned.&lt;/P&gt;&lt;P&gt;  Brian, if still no joy after setting NAT-T in concentrator, we need the config of concentrator.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 15:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976127#M939937</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-02T15:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client behind PIX</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976128#M939939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks folks, I've asked the other side but there is change control to get through before I can test.......I'll keep this updated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Apr 2008 09:18:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-behind-pix/m-p/976128#M939939</guid>
      <dc:creator>molebrian</dc:creator>
      <dc:date>2008-04-03T09:18:59Z</dc:date>
    </item>
  </channel>
</rss>

