Avatar of mwagoner_73
mwagoner_73
Flag for United States of America asked on

Can't connect to remote VPN using Netgear Prosafe client while behind Cisco Pix 501

In our office we have a Cisco Pix 501 firewall / vpn device sitting behind a Cisco 2800 series router.  One of our developers needs to connect to a client VPN using the NetGear Prosafe VPN Client software.  All settings for the vpn connection have been verified but we can't seem to conect.  In the log viewer the following error messages are returned:

- initiating IKE Phase 1 (IP ADDR: xxx.xxx.xxx.xxx)
- SENDING >>>>>>>>> ISAKMP OAK MM (SA, VID, 2x)
- Message not received Retransmitting!
- SENDING >>>>>>>>> ISAKMP OAK MM (Retransmission)

then it just repeats until it times out....

any suggestions or can you help point in the right direction???  Is it something on the Cisco PIX device or the 2800??



Hardware FirewallsCiscoVPN

Avatar of undefined
Last Comment
bkepford

8/22/2022 - Mon
bkepford

Is he trying to connect to the PIX with this client or is he trying to connect to a device outside your network from behind the PIX. Basic question restated is where is the client in refernce to your user.
bkepford

If he is behind your pix by default the PIX blocks ISAKMP traffic from the internal interface.
I believe the command to enable it is "isakmp enable inside"
ck459

Add this command to your config :
fixup protocol esp-ike
If that does not work, attach configs of both router and pix.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
bkepford

ck459 is tha man(or woman),  fixup protocol esp-ike is the right command.
ck459

Still a man and not planning to change that ;-)
mwagoner_73

ASKER
the client we are trying to connect is outside of the PIX on a different network.  I will try the above solutions you mentioned.  thanks!
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
mwagoner_73

ASKER
riddle me this???  why would the netgear sw blow out the Cisco VPN client SW that was already installed on the machine, and is there anyway to have both pieces of client sw on the same system and live in harmony???

thanks again!
ASKER CERTIFIED SOLUTION
bkepford

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.