PIX:L VPN Wizard no maigic for me.

Oct 06, 2006 2 Replies

Not getting very far with Cisco VPN client software (V4.8) and a new PIX



501


Playing with the vpn wizard in the PIX ; does one take the defaults, generally, and will this work with the VPN client software ?


(I'm using :remote access vpn on the outside, Cisco client; IKE encryption



3des,MD5, DH group2; transform set 3des,MD5)


I know the client works, as I'm able to get into my customer's sites with it (not my setup work) ..I'm new to VPN and it's complexities, and am prepared to spend lots of time paying my dues reading on DES and DH and IPSEC, etc, etc .(been reading for days and it's still Greek) but it would be comforting to run a wizard and get something working...... Cisco's docs are not helping so far.


While I'm at it - the PDM doesn't seem very good at setting ICMP; I tell it to echo work from the outside , and I still cant ping it. ( I know it's there , not only from the sh ip, but as I set netcat up as a server on an inside IP and set up statics and an access list - netcat then brings up a shell - nice to see something work )


What software is on the pix. How bout a looksie at the config?

If you are charging customers to learn IPSEC shame on you. Perhaps you are not reading the right documents as IPSEC tunnels have been created millions of time on the PIX firewall. Do you have smartnet? Can you post a config?

You are not wanting to allow echo to return but echo-reply for ping and time-exceeded for traceroute.

Chad;

Thanks for the reply; got it; just a silly typo after a day of frustration. No; I never charge to learn ; I was there setting up a DNS server on a DC and a new switch - but in the valley of the blind a one eyed man , while not king, can earn a honest living doing relatively simple things - I'll try the ICMP commands and then bother you all in few days with other questions on IPsec - thanks again -

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required