09-25-2003 05:59 AM - edited 02-21-2020 12:47 PM
Just wondering if anyone has ran into this issue. Running a PIX 515E-R as firewall / VPN device. We have a 506 connected to it (site to site vpn) and various dynamic clients at remote offices (around 9 connections). When we reach 8 VPN tunnels, the PIX continues to allow connections but does not create a tunnel between it and the client.
09-25-2003 09:58 AM
Don't think it is a limit - you can make 10 IPSec tunnels with a 501, and 20 (IIRC) with a 506. I don't think there is any software limit with the 515. The sites that fail to connect - have they ever connected successfully? Dynamic clients - how big is the ip local pool? Any log entries?
09-29-2003 05:06 AM
Hey thanks for the reply. I did not think there was a limit per say as much as a bug we have run into.
It seems to be that we cannot create more than 8 tunnels. The PIX continues to deploy IP addresses from the local IP pool and allow connections, it just fails to create the tunnel. We have a pool of about 20 IP addresses. All the clients have connected at one time or another. Right now it's like musical chairs first 8 get in, after that they get a connectrion just no tunnel. It's various connection types, dynamic, site-site static, etc. Nothing of note or that I understand has shown up in the log related to this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide