The Interoperable Device object created to represent the PIX firewall has a checkbox under VPN->Advanced for "Support key exchange for subnets". This is checked by default. The PIX FW does not like this when attempting to negotiate the PhaseII/QuickMode SAs. Disable this and push the rules to the firewall.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.