How Do I setup a VPN on a 506/e

Posted on 2005-04-05
Last Modified: 2013-11-16

 I am trying to set up a vpn with a pix 506/e. I am not completely dumb when it comes to cisco equipment but I am unable to get this to work. I am using the vpn wizard. When I try to connect the password requester comes up and accepts the user name and password then nothing happens. With the Cisco client I see it saying ( If I remember correctly) something about establishing a secrure channel and eventually just times out. Help. What would be the simple straight forward steps using the wizard to setup a vpn
Question by:itspecearthlink
    LVL 79

    Accepted Solution

    If you can post your config, I can probably help you out..
    Stepping through the Wizard:
      Select type: Remote AccessVPN
       Select interface: outside
     * Cisco VPN client
      Group Name:  MYVPNGROUP
      * Pre shared key
      Enable Extended Client Authentication  <== uncheck this box
      nothing is checked on this page
     Pool name:  MYVPNPOOL
      Range start:
      Fill in your local primary DNS server, WINS server and default domain name
     Select:  3DES |  MD5  | Group2(1024bit)
     3DES  | MD5
      *ip address
        Interface inside
        ip address  <== whatever is your local LAN
     Add >>
      X Enable split tunneling

    When you setup the client:
    New Entry
      Connection:  <whatever>
      Descript:  <whatever>
      Host:  OUTSIDE IP of PIX
      * Group auth
           Name: MYVPNGROUP
           Pass:  mygrouppassword
           Confirm: mygrouppassword
    Transport Tab
      X Enable Transparent Tunneling
         * IpSec over UDP (NAT/PAT)

    You should not see another username/password prompt again. It should just connect staight away.
    You may have to enable NAT Traversal.
    From the Main GUI window, VPN tab
            Right about the center of the window there is a chekbox
                                         [X] Enable NAT traversal



    Author Comment

    Hi lrmoore

    Thank you, you definetly have me on the right track. However, setting it up with your config it worked fine until I change something and then nothing will work. I have to completely reset the 506/E and then run the VPN wizard again using your config and it will connect. I tried changing the IP address pool to mine with your config and then it won't work. If I try to go back to your pool it still won't work. I again have to completely reset the 506/E and then run the wizard again. It seems like if I change anything I then have to go back and reset the Pix and start over.

    Featured Post

    What Should I Do With This Threat Intelligence?

    Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

    Join & Write a Comment

    If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
    Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now