|
Thanks Vern
access-list inside permit udp host x.x.x.x host 207.25.252.196 eq isakmp access-list inside permit udp host x.x.x.x host 207.25.252.196 eq 4500 access-list inside permit esp host x.x.x.x host 207.25.252.196
The x's will reflect your system's IP address, and you may need to change the 'inside' to reflect whatever firewall interface your system is attached to.
These are the commands we needed to use for a Pix 515 to get this working; the wizard within Ops Nav worked fine for the AS/400 side setup. I've seen one of our systems get confused and the VPN setup stopped working-deleting the universal connection and running the wizard again fixed that.
Hope this helps...
Chad Burrall
AS/400 Administrator
Wheeling-Nisshin, Inc.
|---------+-------------------------------> | | "Adam Lang" | | | <aalang@rutgersinsur| | | ance.com> | | | Sent by: | | | midrange-l-bounces@m| | | idrange.com | | | | | | | | | 04/21/2004 09:04 AM | | | Please respond to | | | Midrange Systems | | | Technical Discussion| |---------+------------------------------->
>------------------------------------------------------------------------------------------------------------------------------|
| |
| To: "Midrange Systems Technical Discussion" <midrange-l@xxxxxxxxxxxx> |
| cc: |
| Subject: Re: IBM Universal Connection and non-Cisco firwalls with NAT? |
>------------------------------------------------------------------------------------------------------------------------------|
If you could, it would be appreciated. We are getting a new iSeries soon and it would be nice to set it up that way as opposed to over the phone line. ----- Original Message ----- From: "Jeff Crosby" <jlcrosby@xxxxxxxxxxxxxxxx> To: "'Midrange Systems Technical Discussion'" <midrange-l@xxxxxxxxxxxx> Sent: Wednesday, April 21, 2004 8:11 AM Subject: RE: IBM Universal Connection and non-Cisco firwalls with NAT?
> > Has anyone actually setup UC with: V5R2, NAT firewall, > > non-Cisco router, private iSeries address? > > We fit that bill _except_ we do have a Cisco router & firewall. It took > well over a year to get it set up. Some of the changes took place on IBM's > end. Now that it's working, it's great. > > If you want to know what the router/firewall settings are, I will have to > contact The Router Guy because I don't know. > > -- > Jeff Crosby > Dilgard Frozen Foods, Inc. > P.O. Box 13369 > Ft. Wayne, IN 46868-3369 > 260-422-7531 > > The opinions expressed are my own and not necessarily the opinion of my > company. Unless I say so. > > > > _______________________________________________ > This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list > To post a message email: MIDRANGE-L@xxxxxxxxxxxx > To subscribe, unsubscribe, or change list options, > visit: http://lists.midrange.com/mailman/listinfo/midrange-l > or email: MIDRANGE-L-request@xxxxxxxxxxxx > Before posting, please take a moment to review the archives > at http://archive.midrange.com/midrange-l.
_______________________________________________ This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/midrange-l or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at http://archive.midrange.com/midrange-l.
_______________________________________________ This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/midrange-l or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at http://archive.midrange.com/midrange-l.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.