We help IT Professionals succeed at work.
Get Started

Cisco VPN Client 4.0.3 to PIX 515 connection fails

averyb
averyb asked
on
2,854 Views
Last Modified: 2013-11-16
I am trying to setup a connection between the Cisco VPN client and a PIX 515E firewall.  I have already successfully setup one using the same client machine to a PIX 501 running 6.3.  I started with the VPN configuration from that machine and worked my way backwards to supported encryption standards, etc . . .

I don't have easy access to the client machine or the ability to attempt a VPN connection, so it's been difficult to troubleshoot.

Here are the pertinent sections of the PIX 515 configuration.  IP addresses have been changed for privacy.

PIX Version 6.1(3)
...
access-list 102 permit ip 10.5.5.0 255.255.255.0 10.5.6.0 255.255.255.240
...
ip address outside A.B.C.125 255.255.255.192
ip address inside 10.5.5.190 255.255.255.0
...
ip local pool vpnpool 10.5.6.1-10.5.6.15
...
global (outside) 1 A.B.C.115-65.169.203.119 netmask A.B.C.192
global (outside) 1 A.B.C.114
nat (inside) 0 access-list 102
...
sysopt connection permit-ipsec
no sysopt route dnat
crypto ipsec transform-set trmset1 esp-des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set trmset1
crypto map mymap 10 ipsec-isakmp dynamic dynmap
crypto map mymap interface outside
isakmp enable outside
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
vpngroup blah address-pool vpnpool
vpngroup blah dns-server 10.5.5.136 10.5.5.134
vpngroup blah default-domain blah.net
vpngroup blah split-tunnel 102
vpngroup blah idle-time 1800
vpngroup blah password ********

VPN Client connection attempts are to A.B.C.125.

All other aspects of the firewall work fine.  As I said above, the same client machine is able to connect to a PIX 501 without any problems.
I debugged the connection attempt and the Phase 1 portion never succeeded.

Also, the 515 firewall is behind a Cisco router, but I do not have any type of access to that.

Thanks for the input.
Comment
Watch Question
CERTIFIED EXPERT
Commented:
This problem has been solved!
Unlock 1 Answer and 5 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE