<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: deadline approaching need help with PIX501e in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090185#M961642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;changed my vpn pool to a 10.10.10.x and that seemed to fix it. thanks to all for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Dec 2008 13:45:04 GMT</pubDate>
    <dc:creator>cworsham80</dc:creator>
    <dc:date>2008-12-09T13:45:04Z</dc:date>
    <item>
      <title>deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090176#M961633</link>
      <description>&lt;P&gt;I am able from an external pc, successfully connect and authenticate locally with my PIX using the Cisco VPN Client software, shows that everything is connected. I am assigned a local IP address of 192.168.0.130 which is the first in my vpn pool. the internal ip of the pix is 192.168.0.1, I also have a pc behind the firewall with an ip of 192.168.0.40, first in its pool. I cannot, however, ping from 192.168.0.130 to 192.168.0.40 nor 192.168.0.1. I can however ping in a single hop the outside IP address of the PIX. From behind the pix i can only ping the inside ip but not outside or to the vpn'd machine. please help. &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090176#M961633</guid>
      <dc:creator>cworsham80</dc:creator>
      <dc:date>2020-02-21T11:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090177#M961634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought I answered this in the other thread, I guess it did not get posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways, it is my understanding the above set up will not work because the VPN Client Local subnet is the same as the remote subnet that you are trying to access through the IPSEC Tunnel. If you look at the routing table on the OS, the subnet shows as a local route and the packets will not be sent across the tunnel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2008 22:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090177#M961634</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-04T22:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090178#M961635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thnx, I reset the PIX to factory defaults and started over on this thing changed my inside addressing to 192.168.2.0 255.255.255.0 i have put back in all the line items i could make sense of. here's what i have so far, i can connect to the vpn, authenticate locally but unable to flow traffic from a pc behind the pix to/from a pc that vpns in. i really need to get this thing up today if at all possible. right now its starting to look like its gonna be a long day&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 17:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090178#M961635</guid>
      <dc:creator>cworsham80</dc:creator>
      <dc:date>2008-12-05T17:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090179#M961636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Result of firewall command: "show run"&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(1)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;hostname catalystpix&lt;/P&gt;&lt;P&gt;domain-name catalystdemo.com&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol pptp 47&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;object-group service VPN tcp-udp&lt;/P&gt;&lt;P&gt;  port-object eq pim-auto-rp&lt;/P&gt;&lt;P&gt;  port-object eq echo&lt;/P&gt;&lt;P&gt;  port-object eq kerberos&lt;/P&gt;&lt;P&gt;  port-object eq discard&lt;/P&gt;&lt;P&gt;  port-object eq sunrpc&lt;/P&gt;&lt;P&gt;  port-object eq domain&lt;/P&gt;&lt;P&gt;  port-object eq tacacs&lt;/P&gt;&lt;P&gt;  port-object eq talk&lt;/P&gt;&lt;P&gt;object-group network VPN1&lt;/P&gt;&lt;P&gt;  description IP Addresses of VPN user&lt;/P&gt;&lt;P&gt;  network-object 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group network Everyone&lt;/P&gt;&lt;P&gt;  network-object 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip any 192.168.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_20 permit ip any 192.168.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 206.248.243.98 eq pptp &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 206.248.243.98 eq netbios-ssn &lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host 206.248.243.98 eq netbios-ns &lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host 206.248.243.98 eq netbios-dgm &lt;/P&gt;&lt;P&gt;access-list 101 permit gre any host 206.248.243.98 &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any eq www any eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_40 permit ip any 192.168.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 206.248.243.98 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 192.168.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool vpn 192.168.2.100-192.168.2.149&lt;/P&gt;&lt;P&gt;pdm location 192.168.2.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;pdm location 192.168.2.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;pdm location 206.248.243.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;pdm location 206.248.243.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;pdm location 206.145.84.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;pdm location 206.145.84.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;pdm location 216.12.23.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;pdm location 216.12.23.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;pdm group VPN1 outside&lt;/P&gt;&lt;P&gt;pdm group Everyone outside&lt;/P&gt;&lt;P&gt;pdm logging informational 100&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 206.248.243.97 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 17:16:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090179#M961636</guid>
      <dc:creator>cworsham80</dc:creator>
      <dc:date>2008-12-05T17:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090180#M961637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;timeout xlate 0:05:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;aaa-server VPN protocol tacacs+ &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.2.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;sysopt connection permit-pptp&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 40 match address outside_cryptomap_dyn_40&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 40 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;crypto map outside_map client authentication LOCAL&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;isakmp policy 20 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 20 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 20 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 20 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 20 lifetime 86400&lt;/P&gt;&lt;P&gt;vpngroup demo address-pool vpn&lt;/P&gt;&lt;P&gt;vpngroup demo dns-server 192.168.2.1 216.12.23.231&lt;/P&gt;&lt;P&gt;vpngroup demo default-domain catalystdemo.com&lt;/P&gt;&lt;P&gt;vpngroup demo idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup demo password ********&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group demo ppp authentication mschap&lt;/P&gt;&lt;P&gt;vpdn group demo ppp encryption mppe 40&lt;/P&gt;&lt;P&gt;vpdn group demo client configuration dns 192.168.0.1 216.12.23.231&lt;/P&gt;&lt;P&gt;vpdn group demo client accounting VPN&lt;/P&gt;&lt;P&gt;vpdn group demo client authentication local&lt;/P&gt;&lt;P&gt;vpdn group demp pptp echo 60&lt;/P&gt;&lt;P&gt;vpdn username demo password ********* &lt;/P&gt;&lt;P&gt;vpdn enable outside&lt;/P&gt;&lt;P&gt;vpdn enable inside&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.2.50-192.168.2.99 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 216.12.23.231 209.145.84.131&lt;/P&gt;&lt;P&gt;dhcpd lease 3600&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 750&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;username demo password XjFBA5DVYjFLLcDW encrypted privilege 15&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:308a765936f2fbee500769cd247dd333&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 17:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090180#M961637</guid>
      <dc:creator>cworsham80</dc:creator>
      <dc:date>2008-12-05T17:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090181#M961638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable this command on the pix"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; isakmp nat-traversal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and try testing again. If still have issues, do post the output of "show crypto isakmp sa" and "show crypto ipsec sa" along with the IP Address that you are trying ping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 18:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090181#M961638</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-05T18:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090182#M961639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;same thing. from outside coming into the pix i get assigned ip 192.168.2.100. Behind the firewall I have a PC with addy 192.168.2.60. I cannot ping in either direction one to another. from .2.60 i can ping .2.1 from 2.100 i cannot. I havea attached the results from the commands as well as a recent show run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 19:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090182#M961639</guid>
      <dc:creator>cworsham80</dc:creator>
      <dc:date>2008-12-05T19:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090183#M961640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any reason why you are using RA vpn pool network the same as your inside LAN network? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would first start suggesting to use different vpn POOL network from that of your inside net 192.168.2.0/24, even if you break down  it just opens up for problems, I have seen issues  using same network inside and RA network in remote access vpns, it is just cumbersome to troubleshoot and most of the time it just don't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from 2.60 you can ping 2.1 fw inside interface thats normal, from 2.100 to ping 2.1 you need &lt;B&gt;management-access inside&lt;/B&gt; statement  but to be honest you have nat-t enabled if you cannot reach 2.60 either 2.60 has a firewall turned of its own or this may not work.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably u would spend less time with a clean RA vpn pool and  move on with proper RA config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Create new network for RA demo tunnel    ,   pick  different net  something like 10.20.20.0/24  and create new pool  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b- update your nat  exempt  access list   to allow the traffic from  new vpn pool network to your LAN networks 192.168.2.0/24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try above suggestion and post results &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 22:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090183#M961640</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-05T22:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090184#M961641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont see anything wrong with the VPN Configuration on the Pix that will block traffic to the 192.168.2.x/24 subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of quick questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. On your vpn client settings for the vpngroup demo, under the tab "Transport", can you make sure that you checked "Enable IPSEC Transparent Tunneling" enabled and IPSEC over UDP option is checked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Also, how are you connecting to the Pix. Are you behind another Pix firewall. If the local PIX is doing PAT/NAT. One option is to configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol esp-ike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the PIX 6.3(x) release notes for more info. as below,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63rnotes/pixrn63.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63rnotes/pixrn63.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;#67762&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#wp1067" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#wp1067&lt;/A&gt;&lt;/P&gt;&lt;P&gt;379&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63rnotes/pixrn63.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63rnotes/pixrn63.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;#65230&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that if you use this "fixup protocol esp-ike" command on the local PIX, then this PIX can only pass a single vpn tunnel outbound and you cannot configure any vpn on this local router at all. For example, you cannot configure the command,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Dec 2008 22:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090184#M961641</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-05T22:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090185#M961642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;changed my vpn pool to a 10.10.10.x and that seemed to fix it. thanks to all for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 13:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090185#M961642</guid>
      <dc:creator>cworsham80</dc:creator>
      <dc:date>2008-12-09T13:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: deadline approaching need help with PIX501e</title>
      <link>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090186#M961643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad my suggestion worked for you, please rate post as resolved, so that others with similar issues can reference from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bst Regads&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 22:37:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deadline-approaching-need-help-with-pix501e/m-p/1090186#M961643</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-09T22:37:54Z</dc:date>
    </item>
  </channel>
</rss>

