For one thing, I doubt your lifetimes match. Add
lifetime 3600
into crypto isakmp and
set security-association lifetime seconds 1200
into crypto map, adjusting figures appropriately and/or change the
isakmpd.conf General section:
Default-phase-1-lifetime= 3
Just for interest, I've set this up successfully using a Zoom X4 (about #45)
using half bridge but originally ran into problems getting the OBSD box to
collect the address via DHCP on the external interface when in this mode (no
such
problems without half-bridge).
Eventually, narrowed it dow
2 matches
Mail list logo