<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: iPhone VPN and Cisco IOS, Part2</title>
	<atom:link href="http://www.thecruftofmybrain.com/2010/05/05/iphone-vpn-and-cisco-ios-part2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thecruftofmybrain.com/2010/05/05/iphone-vpn-and-cisco-ios-part2/</link>
	<description>Purging my mental dust bunnies</description>
	<lastBuildDate>Wed, 25 Jan 2012 13:59:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Peter B</title>
		<link>http://www.thecruftofmybrain.com/2010/05/05/iphone-vpn-and-cisco-ios-part2/comment-page-1/#comment-37676</link>
		<dc:creator>Peter B</dc:creator>
		<pubDate>Wed, 25 Jan 2012 13:59:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecruftofmybrain.com/?p=495#comment-37676</guid>
		<description>Hi all,
   One thing that I have found to be a big problem is the DNS.  It seems that unless you use the split-dns entry on your isakmp config IOS 4+ won&#039;t even attempt to resolve your DNS properly.  I haven&#039;t tested this, but I bet it might fix the DNS problems with the built-in IPSec VPN in MacOS.

Also, FYI... never use a &#039;.local&#039; dns suffix if you need IOS support.  IOS uses &#039;.local&#039; for bonjour stuff and it just won&#039;t work.  There is an apple KB article (TS3389) on this.
Thanks!

crypto isakmp client configuration group BlahBlah
 domain mylocaldomain.private
 split-dns mylocaldomain.private</description>
		<content:encoded><![CDATA[<p>Hi all,<br />
   One thing that I have found to be a big problem is the DNS.  It seems that unless you use the split-dns entry on your isakmp config IOS 4+ won&#8217;t even attempt to resolve your DNS properly.  I haven&#8217;t tested this, but I bet it might fix the DNS problems with the built-in IPSec VPN in MacOS.</p>
<p>Also, FYI&#8230; never use a &#8216;.local&#8217; dns suffix if you need IOS support.  IOS uses &#8216;.local&#8217; for bonjour stuff and it just won&#8217;t work.  There is an apple KB article (TS3389) on this.<br />
Thanks!</p>
<p>crypto isakmp client configuration group BlahBlah<br />
 domain mylocaldomain.private<br />
 split-dns mylocaldomain.private</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Solomon</title>
		<link>http://www.thecruftofmybrain.com/2010/05/05/iphone-vpn-and-cisco-ios-part2/comment-page-1/#comment-21215</link>
		<dc:creator>Solomon</dc:creator>
		<pubDate>Tue, 19 Oct 2010 05:45:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecruftofmybrain.com/?p=495#comment-21215</guid>
		<description>Ignore that Bit just used same template and it worked like a charm, i think you still need to define your nat exemption list though.. 
Let me know if you need more info..</description>
		<content:encoded><![CDATA[<p>Ignore that Bit just used same template and it worked like a charm, i think you still need to define your nat exemption list though..<br />
Let me know if you need more info..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.thecruftofmybrain.com/2010/05/05/iphone-vpn-and-cisco-ios-part2/comment-page-1/#comment-17490</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Thu, 27 May 2010 04:49:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecruftofmybrain.com/?p=495#comment-17490</guid>
		<description>I gave this a shot, but I got some errors saying my destination security zone out-zone and in-zone were not defined.

I think I defined them (still need to apply to interfaces):
zone security in-zone
zone security out-zone
zone security dmz-zone

but then I get error:
Firewall service-policy attachment failed, policy sdm-permit-ip does not exist.

What does your sdm-permit-ip policy look like?</description>
		<content:encoded><![CDATA[<p>I gave this a shot, but I got some errors saying my destination security zone out-zone and in-zone were not defined.</p>
<p>I think I defined them (still need to apply to interfaces):<br />
zone security in-zone<br />
zone security out-zone<br />
zone security dmz-zone</p>
<p>but then I get error:<br />
Firewall service-policy attachment failed, policy sdm-permit-ip does not exist.</p>
<p>What does your sdm-permit-ip policy look like?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

