Core issue
VPN tunnel fails to come up if the configuration is moved from PIX version 6.x to PIX/ASA version 7.x. This issue can be related to the sysopt ipsec pl-compatible command.
When the sysopt ipsec pl-compatible command is used in version 6.x, all PIX firewall features, such as access list control, stateful inspection, and user authentication, are bypassed for IPsec packets only.
Note: The sysopt ipsec pl-compatible command is not supported on version 7.x.
Resolution
Use the no sysopt ipsec pl-compatible command in global configuration mode in order to remove sysopt ipsec pl-compatible from the configuration and resolve this issue.
Product Family
Firewall - PIX 500 series
ASA Hardware & Software
PIX Software Version
PIX version 6.x
PIX version 7.x
ASA Software Version
7.0
7.1