cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
830
Views
0
Helpful
1
Replies

VPN PIX 501 (dyn IP) to Watchguard Firebox (static IP)

___tim___
Level 1
Level 1

Hi,

I'm trying to establish a VPN connection between a PIX 501 and a Watchguard Firebox.

The Watchguard has a static IP, the PIX connects to the internet using a dynamically assigned IP.

For that reason on the PIX-side I configured a host- and domainname and added "isakmp identity hostname". My understanding was that the PIX will use it's FQDN as the ID for the IKE session instead of it's dynamically assigned IP address.

On the Watchguard side I see the following log entries:

iked[146]: FROM 1.2.3.4 MM-HDR ISA_SA ISA_VENDORID ISA_VENDORID

iked[146]: WARNING - Unknown remote gateway ip: 1.2.3.4 id '1.2.3.4'

iked[146]: ACTION - Verify remote gateways in config file

iked[146]: ipsec_rgw_is_dynamic: unable to find id

Also the PIX shows

(identity) local= 1.2.3.4, remote= 5.5.5.5

when enabling a debug crypto.

I think the ID used by the PIX is still the public IP instead of the FQDN and for that reason the Watchguard can't find the matching context for the PIX.

I'd much appreciate any ideas on this one.

Regards,

Tim

1 Reply 1

ebreniz
Level 6
Level 6

Did you try using the option "isakmp identity address"?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: