I setup Cisco PIX 515 in my lab to test IPSec VPN. The PIX is behind a
Linksys WRTP54G router and UDP port 500 is open. I can establish the VPN in
the LAN, but I get not connected error if I test it from a remote office
that is behind another PIX 515E. I am not sure the problem is the Linksys
router or PIX in the office. Any suggestions?
The lab PIX configuration can be found here, http://www.howtonetworking.com/cisco/pixvpnsample.htm
Here are VPN client log.
Cisco Systems VPN Client Version 4.6.01.0019
Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 5.1.2600 Service Pack 2
1 09:58:38.469 05/26/06 Sev=Info/4 CM/0x63100002
Begin connection process
2 09:58:38.979 05/26/06 Sev=Info/4 CVPND/0xE3400001
Microsoft IPSec Policy Agent service stopped successfully
3 09:58:38.979 05/26/06 Sev=Info/4 CM/0x63100004
Establish secure connection using Ethernet
4 09:58:38.979 05/26/06 Sev=Info/4 CM/0x63100024
Attempt connection with server "chicagotech.net"
5 09:58:40.247 05/26/06 Sev=Info/6 IKE/0x6300003B
Attempting to establish a connection with x.x.x.246.
6 09:58:40.557 05/26/06 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Nat-T),
VID(Frag), VID(Unity)) to x.x.x.246
7 09:58:40.587 05/26/06 Sev=Info/4 IPSEC/0x63700008
IPSec driver successfully started
8 09:58:40.587 05/26/06 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
41 09:59:03.341 05/26/06 Sev=Info/4 IKE/0x63000017
Marking IKE SA for deletion (I_Cookie=672CDA295511818F R_Cookie=9ADE594A69BA0090)
reason = DEL_REASON_IKE_NEG_FAILED
42 09:59:03.341 05/26/06 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to x.x.x.246
43 09:59:06.787 05/26/06 Sev=Info/4 IKE/0x6300004B
Discarding IKE SA negotiation (I_Cookie=672CDA295511818F R_Cookie=9ADE594A69BA0090)
reason = DEL_REASON_IKE_NEG_FAILED
44 09:59:06.787 05/26/06 Sev=Info/4 CM/0x6310000F
Phase 1 SA deleted before Mode Config is completed cause by "DEL_REASON_IKE_NEG_FAILED".
0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system
Cisco VPN Client error - The
remote peer is no longer responding ... You receive not
connected when running Cisco VPN client ...
www.chicagotech.net/ciscoclienterrors.htm
Symptom: You are using Cisco
VPN client to establish VPN connection on Cisco PIX. The PIX
assigns ip 192.168.1.1 but you can't ping LAN ip like 10.0.0.10.
...
www.chicagotech.net/ciscorouter.htm
Q: I uses Cisco VPN client
at home to access my company VPN. ... To setup VPN for MS VPN
clients on Cisco PIX, you need to add the following lines.
...
www.chicagotech.net/vpn.htm
3. By default, Cisco VPN
doesn't allow VPN clients access the internet. however, you can setup
split tunnel. Bob Lin, MS-MVP, MCSE & CNE. Related Topics ...
www.chicagotech.net/Q&A/vpn10.htm
What statements are required to
allow a VPN inbound past my Cisco PIX? ... For example,
to add DNS and WINS on a Cisco Firewall PIX, add vpdn group 1
client ...
www.chicagotech.net/vpnsetup.htm