Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: KoRn; ShadowAce
> I just wanted to post it here to see if anyone else might have encountered a similar situation.

I haven't yet, but I have an aging PIX 515E at work that I plan to replace with an ASA 5510 soon, and I suspect I'll encounter a number of similar situations...

Thanks for posting this question. Even though I can't help you on this one from past experience, you've already helped me by making me think about this.

I'll look around and see if I can find anything helpful.

Also thanks to ShadowAce for pinging the tech list...

5 posted on 01/16/2009 7:32:30 PM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 1 | View Replies ]


To: dayglored
"I have an aging PIX 515E at work that I plan to replace with an ASA 5510 soon"

We are in a similar situation, except we used a Cisco Concentrator for our VPN connections. We also have a PIX 515 for our internet usage. We have two different internet pipes, one for internet use and the other for remote access. We had a new 20MB fiber line installed, and decided to use it for our remote access users(and internet for the IT department... hehe). I HIGHLY recommend the ASA. Even though we ran into this issue, it is a SUPER perimeter security device. We just ran into this snag, but I'm SURE we will over come it. If I don't get it resolved by Monday morning, I'm going to call Cisco and have one of their CCIE 'Jedi' network guys get involved. I could have called them today because we have an agreement with them, but like all men, I'll sustain great stress, pain, and suffering before calling for help or asking for directions. lol

6 posted on 01/16/2009 7:56:58 PM PST by KoRn
[ Post Reply | Private Reply | To 5 | View Replies ]

To: ShadowAce; dfwright; dayglored; stylin_geek; N3WBI3
"Even though I can't help you on this one from past experience, you've already helped me by making me think about this."

I was able to get it working! I had to enable IPsec over NAT-T, open inbound UDP 4500, and enable and set an IPsec Prefragmentation Policy.

Thanks to you all for chiming in.

10 posted on 01/17/2009 7:51:48 AM PST by KoRn
[ Post Reply | Private Reply | To 5 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson