<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Frustrated!</title>
	<atom:link href="http://routemyworld.com/2008/09/05/frustrated/feed/" rel="self" type="application/rss+xml" />
	<link>http://routemyworld.com/2008/09/05/frustrated/</link>
	<description>A CCNA/CCNP Blog</description>
	<lastBuildDate>Fri, 17 Feb 2012 15:08:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Steve</title>
		<link>http://routemyworld.com/2008/09/05/frustrated/comment-page-1/#comment-293</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Sat, 06 Sep 2008 15:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://routemyworld.com/?p=191#comment-293</guid>
		<description>what phase of the tunnel is not getting established? Commom issue is the SA times. Cisco is 86400 ( Phase 1) and 3600 (Phase 2) by default. Have you ran some debugs yet? </description>
		<content:encoded><![CDATA[<p>what phase of the tunnel is not getting established? Commom issue is the SA times. Cisco is 86400 ( Phase 1) and 3600 (Phase 2) by default. Have you ran some debugs yet? </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aragoen Celtdra</title>
		<link>http://routemyworld.com/2008/09/05/frustrated/comment-page-1/#comment-294</link>
		<dc:creator>Aragoen Celtdra</dc:creator>
		<pubDate>Sat, 06 Sep 2008 15:30:27 +0000</pubDate>
		<guid isPermaLink="false">http://routemyworld.com/?p=191#comment-294</guid>
		<description>&lt;strong&gt;Barry&lt;/strong&gt;: You really are the man! I did, however, get it to work last night. And guess what? You hit it right on the head. When I finally discovered the &quot;Advanced&quot; setting, the default IKE proposal settings did read just as you said it did (&lt;span class=&quot;postbody&quot;&gt;3DES-SHA1-MODP1024). And because I couldn&#039;t find a way to modify that, I just re-wrote a new IKE policy to match the policy on the EdgeMarc. And that was about 80% of the problem. You were also right about the timers defaulting to 28800. However, It didn&#039;t seem to make a difference when I had the PIX set on 86400. 

&lt;strong&gt;Joey:&lt;/strong&gt; Thanks for trying to help. For a while there I started doubting if I was reading my configs right because I&#039;ve been working on it nonstop. I thought maybe I wasn&#039;t seeing I was supposed to. It turns out that the config was a big part of the problem, as I mentioned above ;) 

If you&#039;re interested, I posted my problem on &lt;a href=&quot;http://techexams.net/forums/viewtopic.php?t=38140&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;techexams.net forum&lt;/a&gt;. You can see my partial configs there. 
&lt;/span&gt;</description>
		<content:encoded><![CDATA[<p><strong>Barry</strong>: You really are the man! I did, however, get it to work last night. And guess what? You hit it right on the head. When I finally discovered the &#8220;Advanced&#8221; setting, the default IKE proposal settings did read just as you said it did (<span class="postbody">3DES-SHA1-MODP1024). And because I couldn&#8217;t find a way to modify that, I just re-wrote a new IKE policy to match the policy on the EdgeMarc. And that was about 80% of the problem. You were also right about the timers defaulting to 28800. However, It didn&#8217;t seem to make a difference when I had the PIX set on 86400. </p>
<p><strong>Joey:</strong> Thanks for trying to help. For a while there I started doubting if I was reading my configs right because I&#8217;ve been working on it nonstop. I thought maybe I wasn&#8217;t seeing I was supposed to. It turns out that the config was a big part of the problem, as I mentioned above <img src='http://routemyworld.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  </p>
<p>If you&#8217;re interested, I posted my problem on <a href="http://techexams.net/forums/viewtopic.php?t=38140" target="_blank" rel="nofollow">techexams.net forum</a>. You can see my partial configs there.<br />
</span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Barry</title>
		<link>http://routemyworld.com/2008/09/05/frustrated/comment-page-1/#comment-292</link>
		<dc:creator>Barry</dc:creator>
		<pubDate>Sat, 06 Sep 2008 15:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://routemyworld.com/?p=191#comment-292</guid>
		<description>At it again, are ya?  Have you tried setting the IKE &amp; IPsec SA lifetime timers to 28800?  I find that non-Cisco devices like to use that timer.  

Otherwise, what do the EdgeMarc Advanced-&gt;IKE-Proposal settings look like (i.e. 3DES-SHA1-MODP1024)?  Not sure how late/long you were working on this, but are you certain both sides match?

HTH,
B-</description>
		<content:encoded><![CDATA[<p>At it again, are ya?  Have you tried setting the IKE &amp; IPsec SA lifetime timers to 28800?  I find that non-Cisco devices like to use that timer.  </p>
<p>Otherwise, what do the EdgeMarc Advanced-&gt;IKE-Proposal settings look like (i.e. 3DES-SHA1-MODP1024)?  Not sure how late/long you were working on this, but are you certain both sides match?</p>
<p>HTH,<br />
B-</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joey B</title>
		<link>http://routemyworld.com/2008/09/05/frustrated/comment-page-1/#comment-289</link>
		<dc:creator>Joey B</dc:creator>
		<pubDate>Fri, 05 Sep 2008 22:02:37 +0000</pubDate>
		<guid isPermaLink="false">http://routemyworld.com/?p=191#comment-289</guid>
		<description>Care to post some sample configs?  Extras eyes can be pretty helpful, understood if you&#039;d rather not and all.

G/l figuring it out!</description>
		<content:encoded><![CDATA[<p>Care to post some sample configs?  Extras eyes can be pretty helpful, understood if you&#8217;d rather not and all.</p>
<p>G/l figuring it out!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

