04-06-2006 04:04 PM
i am trying eazy vpn with pix 7.0.4 ios with a 3640 router. the 3640 router is as aeazy vpn client . and the pix as the eazy vpn server. the client get connected and keeps on asking the xauth parameter. i read in the release notes that that eay vpn requires 12.2 and above secure ios for 806 routers. does the pix also support eaxy vpn client routers fo 800 series only. help required urgent. if this true then pix sucks big time. they are forcing us to buy routers.they are becoming like microsoft. pls help
sebastan
Solved! Go to Solution.
04-06-2006 09:48 PM
According this document
http://www.cisco.com/en/US/products/sw/secursw/ps5299/index.html
Cisco Easy VPN Remote is now available on Cisco 800, 1700, 1800, 2800, 3800, and UBR900 Series routers, Cisco PIX 501 and 506E security appliances, and Cisco VPN 3002 Hardware Clients.
So no support for 3640 ...
M.
Hope that help, rate if it does
04-06-2006 09:48 PM
According this document
http://www.cisco.com/en/US/products/sw/secursw/ps5299/index.html
Cisco Easy VPN Remote is now available on Cisco 800, 1700, 1800, 2800, 3800, and UBR900 Series routers, Cisco PIX 501 and 506E security appliances, and Cisco VPN 3002 Hardware Clients.
So no support for 3640 ...
M.
Hope that help, rate if it does
04-07-2006 06:17 AM
here's my config
my pix is connected acting as a easy vpn server with a webserver connected on the inside interface. the inside interface ip address is 10.1.1.1/24 and the ip address of the web server is 10.1.1.2/24.
the pix outside interface is connected to a 3640 router acting as a easy vpn client.
pix outside interface ip is 1.1.1.1/24 and the interface ip of the router is 1.1.1.2/24.
the 3640's other ethernet interface ip is 20.1.1.1/24 connected a host on 20.1.1.2/24.
i am using pix ios 7.1.2 and 3640 router is having 12.4(5) secure ios.
username cisco password cisco
crypto dynamic dynmap cisco 10 set transform-set cisco
crypto ipsec transform-set cisco esp-des esp-sha-hmac
crypto map cisco ipsec-isakmp dynamic dynmap
crypto map cisco interface outside
isakmp identity address
isakmp enable outside
isakmp policy 1 authentication pre-share
isakmp policy 1 encryption 3des
isakmp policy 1 hash md5
isakmp policy 1 group 2
isakmp policy 1 lifetime 86400
tunnel-group cisco type ipsec-ra
tunnel-group cisco general-attributes
authentication-server-group LOCAL
default-group policy cisco
tunnel-group cisco ipsec-attributes
pre-shared-key cisco
group-policy cisco internal
group-policy attributes
nem enable
password-storage enable
config on the 3640 router
crypto ipsec client ezvpn cisco
group cisco key cisco
peer 1.1.1.1
mode network-extension mode
username cisco pass cisco
int e0/0
ip add 1.1.1.2 255.255.255.0
crypto ipsec client ezvpn cisco outside
no shutdown
int e0/1
ip add 20.1.1.1 255.255.255.0
no shutdown
crypto ipsec client ezvpn cisco inside
the router is all the time prompted for
crypto ipsec client ezvpn xauth
i put in the username and password
but it still keeps on asking the same. i have done my config from a cisco configuration example.
i tried the same with pix ios 6.3 it works fine. pls help me out if possible. i have spend a entire night over this. thank u for ur response. waiting for ur reply.
sebastan
04-08-2006 04:51 AM
hi there i used this same router with pix ios version 6.3 but it still worked fine.even 2600 series router worked fine as a easy vpn client. the list of easy vpn clients u have given is it in respect with pix 7.0 ios.
can u pls a geta list of ios routers that are supported as easy vpn clients with pix 7.0 ios. pls help . thank u once again .waiting for ur reply.
sebastan
08-23-2007 01:26 PM
Hi,
I meet the same problem as you :
ezvpn on pix v7 and C2800 as ezvpn client:
ask me username and passwor
Do you success in solving your problem?
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide