Re: Cisco VPN Client to 3005 Concentrator

Aida Lumbreras <[email protected]> Wed, 23 Mar 2005 01:07:12 -0600
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
Hi Denver,

Per the logs, the client is failing the initial IKE exchange. Is it
possible that this
going through the firewall, it could be preventing some port numbers
from getting
through?

Please double check that on the pix firewall you are permiting
UDP/4500 on the outside access-list, we need this port for NAT-T
negociation.


-- 
AĆ­da Lumbreras 
VPN Team, CiscoTAC
Cisco Systems