I'm not sure if this is exactly what you are referring to Craig, but it might help. We also have had problems doing VPN Client connections behind PAT. Its only in places where the DSL/Cable router cannot support PAT on unknown ports, like UDP 10000 which is default for VPN 3000 connections. Linksys routers are an example. The workaround is in 3000 concentrator version 3.5 where you can do IPSec via TCP. So you can setup PAT on known ports, like TCP port 80.
Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=45960&t=45927 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

