No client is able to establish a VPN connection through the ASA unless I giive them a static translation. I know that the distant ends are allowing NAT-T connections because i see UDP 4500 when the clients are statically translated. Under normal configuration using PAT, the ASA translates the packet from ex. 192.168.1.1:500 to x.x.x.8:1 and it never works. Any ideas??