Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
"phase 2 packet is a duplicate of a previous packet " means the client had passed the isakmp policy phase (phase 1). Something wrong with the xauth (phase 2). Try to use the LOCAL authen for the xauth. If that works ok with LOCAL, something wrong b/t...
On cisco IOS routers and PIX, only permit statements of the ACL will be downloaded to the vpn client as the splittunneling policy. Deny statements are simply ignored.
You can still do NAT after IPSec encryption. The key here is to use protocol ESP not AH as AH would authenticate the ip header and NATting the ip address would fail the AH authentication.The link on CCO will work. Just one more thing, when configurin...