Posted on 2005-04-28
Last Modified: 2013-11-16
hello everyone,

i am trying to establish a sitetosite vpn between a PIX515E and SONICWALL firewall. i was able to establish sitetosite vpn between two pix firewall. but i am not able to do this when its between pix and sonicwall. To guide me in this, i have used the docuement available in sonicwall website. But still no use. if anyone have attempted this before or who got expertise in this, please help. In addition to this if anyone can help by giving some hints on troubleshooting the vpn connection issues between PIX and SONICWALL, i would be grateful.

Question by:GEMINI-INDIA
    LVL 79

    Expert Comment

    Troubleshooting tools on the PIX side:

     sho cry is sa
     sho cry ip sa
     debug cry isa

    Check to see if Perfect Forward Secrecy is enabled on the Sonicwall. The PIX does not enable by default, but many other firewalls do.. If so, just un-check it on the Sonicwall..


    Author Comment

    thanks for the response. i checked SONIC, PFS is disabled there too.
    LVL 5

    Expert Comment

    If the interoperability does not work try this out.

    I have tried this between PIX 515E (located in Europe) and SonicWall 2040 (located in Middle East, where we are located) and it worked.

    1) Have an internal server mapped to external address as VPN server.
    2) Get the public address/ gateway address of the external firewall/router.
    3) On the SonicWall create a rule that allows inbound connections through PPTP i.e. port number 1723 (TCP) only from that public address to the VPN server.
    4)Activate the connection (which is self in SonicWall) and try to connect to the VPN server.

    N.B. you need not have a separate server for this . You can use your file and print server as VPN server.

    With reagrds to interoperability I will try to find sort this issue


    Author Comment

    i am not using PPTP. The pix and sonic should act as the vpn server allowing ipsec/ike.

    Author Comment

    hello all,

    i sorted out the problem. the issue was in the advanced settings screen of sonic, they have entered my pix external interface ip address as gateway. actually it should be and nothing else. ie no settings has to be changed in advanced settings screen of sonic wall vpn configuration.
    LVL 79

    Expert Comment

    Good work! Sorry we couldn't have been more help. You can post a Q in community support and ask a moderator to PAQ this question since you answered it yourself..

    Thanks for the follow up..
    LVL 1

    Accepted Solution

    PAQed with points (150) refunded

    Community Support Moderator

    Featured Post

    Gigs: Get Your Project Delivered by an Expert

    Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

    Join & Write a Comment

    Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
    If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…
    In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now