Re: Trouble with ISA2004 site-to-site to Cisco Pix 501

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi,

This is the normal behaviour, as PIX creates the IPSEC Tunnel only when
"relevant" traffic is generated towards its IPSEC peer.

http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/ipsecvpn.mspx

Is each one set up as gateway to the other?
Which is one the originator?


"wrkinprgrs" <blaze@xxxxxxxxxxxxx> wrote in message
news:1130423464.673181.274110@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> We have an ISA2004 server running on Windows Server 2003 and it has 3
> existing site to site vpn connections on it now. We are setting up a
> 4th and this one is giving us trouble. The other end is running Cisco
> Pix 501 and we can establish the IPSEC site to site but they have to
> initiate all connections to us we cannot connect to them. Eg. Once
> they initiate a ping to one of our machines (which is successfull) we
> can then and only then ping them from that machine. Other machines
> still cannot ping them. If they ping the other machines on our
> end...then we are able to ping from them as well. I have asked them if
> they set us up as a NAT which seems to make sense to me as to why all
> unsolicited traffic from us is blocked but they say that is not the
> case. We are not familiar with Cisco Pix especially command
> line....totally ISA experience here....anyone know what could be wrong
> on the Cisco side? (of course assuming its not ISA...since ISA is open
> to their network setup as a route network).
>


.



Relevant Pages

  • PING to inside address goes thru translation and timesout
    ... I have just installed a PIX 501 and I'm having an odd issue with PING ... However when I try and ping these two machines from within my inside ... translation defined for them that have an issue. ...
    (comp.dcom.sys.cisco)
  • weird results while ipsec + ipfv_nat (nat before vpn)
    ... we need to see some http/s resources behind the Cisco PIX IPSEC ... trying to ping IPSEC PEER from LAN ... c.c.c.1 reply packets are coming in and are decrypted but replies doesn't reach ... tcpdump: verbose output suppressed, use -v or -vv for full protocol decode ...
    (freebsd-net)
  • No AuthIP user authentication of Ping with IPSec?
    ... It appears on Server 2008-R2 and Windows 7 that you cannot require IPSec ... user authentication for inbound ICMPv4 echo requests without causing ... then the incoming ping packets are dropped. ...
    (microsoft.public.windows.server.security)
  • Re: More VPN routing issues... )-:
    ... I made some corrections to my Lifetime values and all was good in the ... Firstly I am really a router person - the pix is a whole ... - Communications between the two pixes for IPSEC ... routes at all points in the path. ...
    (comp.dcom.sys.cisco)
  • Re: Win 2003 Server only talking with local Subnet
    ... There are no IPSec filters or policies running. ... with one IP Address and it can ping the firewall without issue. ... IPv4 Route Table ...
    (microsoft.public.windows.server.networking)