[prev in list] [next in list] [prev in thread] [next in thread] 

List:       vpn
Subject:    [VPN] Re: Pix to Pix VPN Question
From:       Michael Batchelder <piranhabros () yahoo ! com>
Date:       2003-10-31 21:19:17
[Download RAW message or body]

 
> Message: 1
> Date: Wed, 29 Oct 2003 11:35:03 -0000
> From: "Laneille&Joe" <laneille@jrossi.demon.co.uk>
> Subject: [VPN] Pix to Pix VPN Question 
> To: <vpn@lists.shmoo.com>
> Message-ID: <000501c39e10$b2834ac0$0a01a8c0@joehome>
> Content-Type: text/plain; charset="us-ascii"
> 
> Hi
>  
> Ok where to start.

Posting the configs of the two PIXen in question would make
answering your question much easier.  You can scrub external IP
addresses and anything else you don't wish to publicly announce.

Possibly your problem is with NAT.  A quick way to see if your
VPN isn't working because of NAT is to add the following command
in both pixen:

sysopt ipsec pl-compatible

and see if everything starts magically works...  If that's the
case, you should 1) take out that command and 2) make the
correct "nat 0 access-list" statements.

Then don't forget to clear xlate, and life should be good.

Binky

__________________________________
Do you Yahoo!?
Exclusive Video Premiere - Britney Spears
http://launch.yahoo.com/promos/britneyspears/
_______________________________________________
VPN mailing list
VPN@lists.shmoo.com
http://lists.shmoo.com/mailman/listinfo/vpn
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic