Is trying to configure an IPSec tunnel between a Netscreen and a Pix using certificates for authentication a fool's errand? Myself and a colleague have been working this off and on for several days. A tunnel using pre-shared keys comes up just fine but when using certs issued by his CA, we get obscure errors. When I ping Cisco tech support about it, they reply "not supported". Are they just being obstructive or do wizards on this list know of technical reasons why this won't work?

