Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX OS 6.3 pb with PAT

Status
Not open for further replies.

mbilgrav

IS-IT--Management
Apr 24, 2004
110
DK
Hi groupmembers,

I got a really big problem.
I have seen this both working on some PIX's and not working on others, all running 6.3.x

common is that I run interface PAT.
the PIX are internet gateways, so does not have any "strange" or unusual config, just plain global and Nat statement for outbound webaccess in HotSpot solutions.

Several users use Cisco VPN client towards VPN3000 headends.
UDP encap on both udp/10000 and 4500 (NAT-T)
The first user connects just fine.
And this is the real problem:
Whenever a second user tries to connect via VPN the PIx report Protmap translation creation failed !!
I can see in show xlate, that udp/500 is PAT'ed to ... udp/500 !! so no PAT oon low ports !
OMG this problem should have been solved in rel 6.2 !

What is going on here ?

I am very upset about this problem, as it should not have been there.
I have tried 6.3.3 and 6.3.4



 
no - this is the old PAT problem, were the PIX doesnt do PAT on low port numbers.

It is udp500 ISAKMP not ESP, which is encapped...
 
After getting a useless Cisco TAC engineer, I decided to go and downgrade the pix to latest GD version (6.2.4)
This works !!
Just to emfrase that they did fix it way back.

The strange thing then happends as I start flashing one version at a time. Here is a list of the order:

633 no go
634 no go
633_132 no go
624 GO
631 GO
633_109 GO (this is strange)
634 GO (!)

So I can only conclude that I have had a bad flash, that after several re-writes came back to order.

If I see this onve more I surely will go for a RMA.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top