VPN question(s)

Hi there !

I'm trying to establish an IPsec tunnel between a 1710 and a PIX 515. So far, so quite easy ... BUT the 1710 resides behind a DSL router and therefore doesn't have direct WAN access.

I put the crypto map on the internal interface and I seem to get some SAs established but

Jan 10 15:09:12: %CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from *.*.*.* failed its sanity check or is malformed

doesn't sound good. Does this have a chance to work through a NATing DSL router. I could also offer a PIX 501 instead of the 1710 but that shouldn't make a difference in this case, should it?

Can anybody help?

TIA

fw

read more and respond »

Posted 5 years ago by Frank Winkler in Cisco Systems

Report misuse

Image for VPN question(s)