Cisco VPN client can't connect to our bank cisco gateway through our ISA 2004.

Hi!

The problem is: we have ISA 2004 on our server installed (MS Windows 2003 server, Domain controller) and internal corporate network 192.168.x.x. (all MS WinXP sp1) and Cisco Systems VPN client 3.0.3 (A) installed on the client computer. The cisco Log viewer writes:

11    08:58:58.207  11/05/04  Sev=Warning/2      IKE/0xE3000079
Exceeded 3 IKE SA negotiation retransmits... peer is not responding

12     08:58:58.270  11/05/04  Sev=Warning/3      DIALER/0xE3300015
GI VPN start callback failed "CM_PEER_NOT_RESPONDING" (16h).

What I must do on ISA 2004 to gain access to remote gateway?
ithorrorAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

lrmooreCommented:
This might help.
http://support.microsoft.com/default.aspx?scid=kb;en-us;812076

I can't find anyhting that will help with 2004...
Is it in just proxy mode? You might be out of luck if so...
0
ithorrorAuthor Commented:
Unfortunatly, this article about ISA 2000 but not about ISA 2004! I've tried but it didn't help me. ((
Anybody knows how to solve this problem?
0
MikeKaneCommented:
I found this, it might be helpful to your issue.


http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/ipsecvpn.mspx#EDAA

It really about VPN tunnels using IPSEC but there are some sections about setting up the clients through 2004 as well.  

Good luck.


0
Simple Misconfiguration =Network Vulnerability

In this technical webinar, AlgoSec will present several examples of common misconfigurations; including a basic device change, business application connectivity changes, and data center migrations. Learn best practices to protect your business from attack.

ithorrorAuthor Commented:
This article is not currently what I need MikeKane!

I need just to let my ISA 2004 translate statically some ports from internal client to the cisco gateway on the bank side.
That what they say. If it will be the ISA 2000 then it's easy to organize it. But here ISA 2004...............
0
MikeKaneCommented:
If you have an outbound rule set to allow all outbound traffic, then you are done.  You can throw a sniffer on the outside of the ISA to see if traffic is getting out of the ISA sever.    I think it is from the error messages you have.  

Try using Cisco VPN 4.x on the clients, not the 3.03 you have installed.  

And just for FYI:
http://www.microsoft.com/technet/community/chats/trans/isa/isa_092204.mspx
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
lrmooreCommented:
How's it going? Have you found a solution? Do you need more information?
Can you close this question?

http://www.experts-exchange.com/help.jsp#hs5

Thanks for attending to this long-forgotten question.

<-8}
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.