cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
366
Views
0
Helpful
2
Replies

PIX 515E-R VPN, IPSEC / IKE Tunnel limit

lorettamurphy
Level 1
Level 1

Just wondering if anyone has ran into this issue. Running a PIX 515E-R as firewall / VPN device. We have a 506 connected to it (site to site vpn) and various dynamic clients at remote offices (around 9 connections). When we reach 8 VPN tunnels, the PIX continues to allow connections but does not create a tunnel between it and the client.

2 Replies 2

mostiguy
Level 6
Level 6

Don't think it is a limit - you can make 10 IPSec tunnels with a 501, and 20 (IIRC) with a 506. I don't think there is any software limit with the 515. The sites that fail to connect - have they ever connected successfully? Dynamic clients - how big is the ip local pool? Any log entries?

Hey thanks for the reply. I did not think there was a limit per say as much as a bug we have run into.

It seems to be that we cannot create more than 8 tunnels. The PIX continues to deploy IP addresses from the local IP pool and allow connections, it just fails to create the tunnel. We have a pool of about 20 IP addresses. All the clients have connected at one time or another. Right now it's like musical chairs first 8 get in, after that they get a connectrion just no tunnel. It's various connection types, dynamic, site-site static, etc. Nothing of note or that I understand has shown up in the log related to this.