cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
929
Views
0
Helpful
1
Replies

IPSec NAT-T and IPSec LAN-to-LAN problem

al-johnston
Level 1
Level 1

I have a Cisco 3005 which has been used to run PPTP connections w/MIcrosoft's VPN client for company employees who are on the road. We also have several small offices that connect via IPSec LAN-to-LAN. Now I have to setup a remote site that is sitting behind a NAT firewall. I have been trying to setup IPSec NAT Transparency to run with the Cisco VPN client, but the same error keeps coming up:

"Xauth required but selected Proposal does not support xauth,

Check priorities of ike xauth proposals in ike proposal list."

When I try to change the IKE proposal list priorities to upgrade an XAUTH proposal, it causes all kinds of problems with the IPSec LAN-to-LAN connections.

Does the problem lie with the two types of IPSec connections I am trying to run? Any suggestions or solutions on how to solve this problem?

1 Reply 1

drolemc
Level 6
Level 6

Go to Configuration > System > Tunneling Protocols > IPSec > IKE proposals. Once there, select the Active proposal used by Group and check if you are using XAUTH. To change the config, click the modify button and choose "Preshared Keys (XAUTH)" under Authentication mode.

Review Cisco Networking for a $25 gift card