Re: [fw-wiz] Pix - portmap translation creation failed

From: Javier Sanchez Llera (jsanchez_at_myalert.com)
Date: 02/02/04

  • Next message: Joe Ippolito: "Re: [fw-wiz] Pix - portmap translation creation failed"
    To: "Crissup, John (MBNP is)" <John.Crissup@us.millwardbrown.com>
    Date: Mon, 02 Feb 2004 17:50:21 +0100
    
    

    Hi,

    you should use the option "sysopt connection permit-ipsec" on your
    config to let ipsec traffic pass through the pix. You should take car of
    the nat-travsersal options that your vpn-client should have.

    Cheers

    Javier Sanchez Llera
    jsanchez@myalert.com
    Systems Administrator
    MyAlert.com

    El lun, 02-02-2004 a las 16:38, Crissup, John (MBNP is) escribió:
    > OK, folks, need your help. We have a user trying to VPN out of our network
    > using a Netscreen or SafeNet (??) client (Sorry, got that second hand and am
    > not up on Netscreen products). I'm seeing a syslog entry being generated by
    > the PIX for message %PIX-3-305006. The exact error follows (appropriately
    > scrubbed)...
    >
    > %PIX-3-305006: portmap translation creation failed for protocol 50 src
    > inside:172.20.1.1 dst outside:A.B.C.D
    >
    > My PIX 520 (Ver 6.3.1) is configured to use PAT for all Internet bound
    > traffic. A search of Cisco's site turns up nothing about this particular
    > error except a bug report that the documentation needs to be updated to show
    > this error. Can anyone offer some direction on how to resolve this?
    >
    > As always, thanks in advance for any assistance you can offer.
    >
    > --
    >
    > John M. Crissup
    > Network Systems Engineer
    > Global Network Services
    >
    > Millward Brown
    > 535 E. Diehl Rd.
    > Naperville, IL 60563
    >
    > ====================================================
    > This email is confidential and intended solely for the use of the
    > individual or organisation to whom it is addressed. Any opinions or
    > advice presented are solely those of the author and do not necessarily
    > represent those of the Millward Brown Group of Companies. If you are
    > not the intended recipient of this email, you should not copy, modify,
    > distribute or take any action in reliance on it. If you have received
    > this email in error please notify the sender and delete this email
    > from your system. Although this email has been checked for viruses
    > and other defects, no responsibility can be accepted for any loss or
    > damage arising from its receipt or use.
    > ====================================================
    >
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    >

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Joe Ippolito: "Re: [fw-wiz] Pix - portmap translation creation failed"

    Relevant Pages

    • Re: This road pricing scam
      ... could get the black boxes to download their details over the mobile network. ... To be working It has to be storing data and reporting this data and responsive to a wireless communication network. ... GPS may not work in certain locations but if the device moved between different locations without any intermediate points it would look strange. ... If the police stopped a car where the device had suddenly started to work when they stopped it I think they would be entitled to mount a more thorough search for a jamming device. ...
      (uk.legal)
    • Re: General
      ... In this case, think of the Pocket PC as a car, then. ... Paul T. ... It sounds to me like there is a problem with the ROM update for your ... volume of stuff that interacts with network adapters on your PC. ...
      (microsoft.public.pocketpc.activesync)
    • Re: transport planning favours cars
      ... saying those in the sticks don't deserve to be able to get broadband. ... The network is simply nowhere near adequate. ... an 'adequate' road network in your sense. ... A typical car passenger is greener than a typical bus or train passenger, and how efficient is a bike when you need to use a train to carry you and it for most of many journeys. ...
      (uk.rec.cycling)
    • Re: Unable to login
      ... It seems your issue is not the network but the lack of an alternative ... One little mishap and you're locked out of your own car! ... and create a secondary admin account and lock the password ... Last known good configuration was initial purchase ...
      (microsoft.public.win2000.networking)
    • Re: Hey Neighbor, Stop Piggybacking on My Wireless
      ... Simple analogy....I go to the supermarket and leave my car keys in the ... The stranger who took it is a thief, which doesn't begin to address what ... situation and anyone who doesn't secure a wifi network can almost ... to disagree without being or becoming disagreeable. ...
      (soc.retirement)