I probably need to add to this question.
I am not blocking Port UDP 500, A certain British ISP is. Unfortunately a few of our support engineers chose them as their ISP and cannot now talk back to base. I need to get thier VPN Clients working whilst they change their provider. I am gambling on the fact that the ISP is blocking on Port Numbers.
I know the Cisco VPN Client on Win 2k has an option to use IPSec over a specific TCP port. I want to use this feature. I just dont know how to configure the TCP port on the PIX. I have the rest of the Pix set up correctly I suspect 2 things either
a. The IPSec over TCP is not supported on Pix ony VPN3000 concentrators
b. I need an access-list, ipsec or similar command to define which port the clients connect to.
Main Topics
Browse All Topics





by: geoffrynPosted on 2003-03-12 at 17:09:35ID: 8124246
ISAKMP is a standard port. I do not think that the PIX supports any means of changing the listening port. Why would you feel the need to block 500 UDP in the first place?