Hi all, We are using Cisco VPN 3015 concentrator with 3.0.3.3des software and a 3.0.3B Cisco VPN client. We have a NAT device (1600 router with NAT) between the VPN client and the VPN concentrator. If I use preshared keys and with IPSec-over-NAT enabled, I am able to connect to the VPN concentrator and access servers. However while using Digital certificates the same doesn't hold true. At times when the link between VPN client and VPN cocentrator is less congested (ping response times less than 62ms) , I am able to connect to the VPN concentrator without errors (when using IPSec-over-NAT and digital certificates) However if the link is little congested(ping response times in the range 63ms to 110ms) I cannot establish the connection. It err's out saying "Duplicate Phase1 packet detected". Can anyone help on this. We are facing this in our live environment hence the urgency. Also If I connect my connection never gets timed-out.(by default the timeout value for a internal user is 28800ms or 8 hours) Thanks and regards... Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=18224&t=18224 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

