cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
379
Views
0
Helpful
2
Replies

Client -> PIX connection help

admin_2
Level 3
Level 3

When using the Cisco VPN Client (4.0.4), I receive the dreaded Reason 412: The remote peer is no longer responding. I am completely unable to connect. No connection is ever established. I've read where some have connected only to have their connections drop, but I can't seem to get anywhere.

we're using ATM via an LS1010, which goes to a 3725, to a PIX 515. Below is a copy of what I believe are relevant portions of the PIX config. Any help would be greatly appreciated!

btw, at this point, I'm not concerned about using any XAUTH (radius, tacacs+, etc), or using our CA (win2k3), though that will be soon to follow.

2 Replies 2

drolemc
Level 6
Level 6

The message could mean a lot of things. One of the possibilities is a configuration error, especially when after initiation, the client never connects to the remote IPSec endpoint. You should make sure that the transform sets are correct. Also, if you are using AES, make sure that a supported key size is defined. (I think 192 bit key is not supported)

ehirsel
Level 6
Level 6

Unapply the outside crypto map and do this:

I would remove this: crypto dynamic-map outside_dyn_map 40 set transform-set ESP-DES-MD5

and adjust the crypto map seq number from 65535 to 65000 for the outside map, as maybe that 65535 value is a reserved or default one.

Then reapply the crypto map and run the pix debug crypto isakmp and debug crypto ipsec commands. Have the client connect and let me know what you find.

Review Cisco Networking for a $25 gift card