Our vpn3060 is running under constantly heavy load. We only have setup the vpn3000 for ras vpn (no ssl and Site2Site vpn)with about 2000 clients. Frequently we are getting the "ike concurrent session limit exceeded" message from the vpn3000. As we already know from cisco there is a build in rate limit for ike negotiation which is set up to 40/per sec. I am thinking of migrating to ASA5540 which is the recommended successor for the vpn3000 platform. Has anyone knowlege about the "ike conurrent session limit" on a ASA 5540?